← back
CVE-2023-54347

OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass

CVSS 8.7 HIGHEPSS 0.5%CWE-307
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 0.5%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
05 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically test username and password combinations without account lockout restrictions.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Open-Emr · OpenEMR
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →