vendor:
OpenEMR
by:
Emre ÖVÜNÇ
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: OpenEMR
Affected Version From: 5.0.1
Affected Version To: 5.0.1
Patch Exists: YES
Related CWE: N/A
CPE: a:openemr:openemr:5.0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
OpenEMR 5.0.1 – ‘controller’ Remote Code Execution
To exploit vulnerability, someone could use 'http://[HOST]/controller.php?document&upload&patient_id=00&parent_id=4&' post request to upload malicious php codes.
Mitigation:
Update to the latest version of OpenEMR