Show filters
129 Total Results
Displaying 81-90 of 129
Sort by:
Attacker Value
Unknown

CVE-2019-8371

Disclosure Date: September 16, 2019 (last updated November 27, 2024)
OpenEMR v5.0.1-6 allows code execution.
Attacker Value
Unknown

CVE-2019-3968

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
0
Attacker Value
Unknown

CVE-2019-3966

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
0
Attacker Value
Unknown

CVE-2019-3963

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
0
Attacker Value
Unknown

CVE-2019-3965

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
0
Attacker Value
Unknown

CVE-2019-3967

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.
0
Attacker Value
Unknown

CVE-2019-3964

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
0
Attacker Value
Unknown

CVE-2019-14529

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
Attacker Value
Unknown

CVE-2018-17179

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
0
Attacker Value
Unknown

CVE-2018-17181

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
0