vendor:
OpenEMR
by:
xistence
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OpenEMR
Affected Version From: 4.1.1 Patch 14 and lower
Affected Version To: 4.1.1 Patch 14 and lower
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:openemr:openemr:4.1.1_patch_14
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS 5.9 32-bit
2013
OpenEMR 4.1.1 Patch 14 Multiple Vulnerabilities
The 'authProvider' parameter in the 'interface/main/main_screen.php' POST script is vulnerable to SQL Injection. A valid 'authPass' password is needed before injection is possible. The POST request below could be used to retrieve passwords from other users and gain higher privilegies.
Mitigation:
Upgrade to OpenEMR 4.1.2