Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-32104

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A SQL injection vulnerability exists (with user privileges) in interface/forms/eye_mag/save.php in OpenEMR 5.0.2.1.
Attacker Value
Unknown

CVE-2021-32102

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
Attacker Value
Unknown

CVE-2021-32101

Disclosure Date: May 07, 2021 (last updated February 22, 2025)
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.
Attacker Value
Unknown

CVE-2020-36243

Disclosure Date: February 07, 2021 (last updated February 22, 2025)
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.