← Back

Openemr

openemr

Vendor: Open Emr • 217 CVEs

CVEs (217)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Emr
1Openemr
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
1Open Emr
1Openemr
Nov 21, 2024
Oct 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
1Open Emr
1Openemr
Nov 21, 2024
Oct 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
1Open Emr
1Openemr
Nov 21, 2024
Oct 4, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, fixed in version 5.0.2.1
1Open Emr
1Openemr
Nov 21, 2024
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenEMR v5.0.1-6 allows XSS.
1Open Emr
1Openemr
Nov 21, 2024
Sep 16, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
OpenEMR v5.0.1-6 allows code execution.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This could allow an attacker to execute arbitrary code in the context of a user's session.
1Open Emr
1Openemr
Nov 21, 2024
Aug 13, 2019
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file...Show more
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.Show less
1Open Emr
1Openemr
Nov 21, 2024
Aug 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
1Open Emr
1Openemr
Nov 21, 2024
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
1Open Emr
1Openemr
Nov 21, 2024
May 17, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
1Open Emr
1Openemr
Nov 21, 2024
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
1Open Emr
1Openemr
Nov 21, 2024
Apr 2, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attacke...Show more
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..Show less
1Open Emr
1Openemr
Nov 21, 2024
Aug 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attacke...Show more
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..Show less