The administration module in OpenMRS 2.1 Standalone Edition allows remote authenticated users to obtain read access via a direct request to /admin.Referenceshttp://packetstormsecurity.com/files/128748/OpenMRS-2.1-Access-Bypass-XSS-CSRF.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/97693http://www.securityfocus.com/bid/70664