RULE(RULE ID:312586)

Rule General Information
Release Date: 2016-11-21
Rule Name: Openemr Globals.php Authentication Bypass Vulnerability (CVE-2015-4453)
Severity:
CVE ID:
Rule Protection Details
Description: interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive information via an ignoreAuth=1 value to certain scripts.
Impact: An attacker can abtain more privileges which he is not entitled to by exloiting the vulnerability, such as executing arbitrary code, deleting files, viewing sensitive information, changing configurations.
Affected OS: Windows
Reference: SecurityFocusBID:75299
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://www.open-emr.org/wiki/index.php/OpenEMR_Patches