Show filters
135 Total Results
Displaying 71-80 of 135
Sort by:
Attacker Value
Unknown

CVE-2020-13569

Disclosure Date: January 28, 2021 (last updated February 22, 2025)
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can lead to the execution of arbitrary requests in the context of the victim. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-19364

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Attacker Value
Unknown

CVE-2020-13567

Disclosure Date: January 04, 2021 (last updated February 23, 2025)
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-16795

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
Attacker Value
Unknown

CVE-2019-16404

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.
Attacker Value
Unknown

CVE-2019-16862

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
Attacker Value
Unknown

CVE-2019-17409

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
Attacker Value
Unknown

CVE-2019-17197

Disclosure Date: October 05, 2019 (last updated November 27, 2024)
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
Attacker Value
Unknown

CVE-2019-17179

Disclosure Date: October 04, 2019 (last updated November 27, 2024)
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1
Attacker Value
Unknown

CVE-2019-8368

Disclosure Date: September 16, 2019 (last updated November 27, 2024)
OpenEMR v5.0.1-6 allows XSS.