Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2018-1000020

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
0
Attacker Value
Unknown

CVE-2018-1000019

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
0
Attacker Value
Unknown

CVE-2017-12064

Disclosure Date: August 01, 2017 (last updated November 26, 2024)
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.
0