Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2021-32104
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
0
Attacker Value
Unknown
CVE-2021-32102
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
0
Attacker Value
Unknown
CVE-2021-32101
Disclosure Date: May 07, 2021 (last updated February 22, 2025)
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
0
Attacker Value
Unknown
CVE-2020-36243
Disclosure Date: February 07, 2021 (last updated February 22, 2025)
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.
0