CVE-2021-40352 | OpenEMR 6.0.0 Message pnotes_print.php noteid resource injection (EDB-50260)
A vulnerability was found in OpenEMR 6.0.0. It has been classified as problematic. Affected is an unknown function of the file pnotes_print.php of the component Message Handler. The manipulation of the argument noteid leads to improper control of resource identifiers.
This vulnerability is traded as CVE-2021-40352. Access to the local network is required for this attack to succeed. Furthermore, there is an exploit available.