Show filters
129 Total Results
Displaying 1-10 of 129
Sort by:
Attacker Value
High
CVE-2019-14530
Disclosure Date: August 13, 2019 (last updated November 27, 2024)
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.
1
Attacker Value
Very High
CVE-2018-15139
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
1
Attacker Value
Moderate
CVE-2018-15142
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in the traversed directory.
1
Attacker Value
Unknown
CVE-2024-0875
Disclosure Date: November 15, 2024 (last updated November 20, 2024)
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.
0
Attacker Value
Unknown
CVE-2023-2950
Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
0
Attacker Value
Unknown
CVE-2023-2949
Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
0
Attacker Value
Unknown
CVE-2023-2948
Disclosure Date: May 28, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
0
Attacker Value
Unknown
CVE-2023-2947
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
0
Attacker Value
Unknown
CVE-2023-2946
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
0
Attacker Value
Unknown
CVE-2023-2945
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
0