Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without authentication and rate limiting.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsma-22-095-01 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2022-04-11 13:15
Updated : 2022-04-18 06:49
NVD link : CVE-2022-1067
Mitre link : CVE-2022-1067
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
lifepoint
- patient_portal