CVEs (218)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php. |
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF t...Show more |
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker...Show more |
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchit...Show more |
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php vi...Show more |
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a refle...Show more |
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a pa...Show more |
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to o...Show more |
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter. |
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component. |
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1. |
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1. |
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1. |
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. |
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1. |
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |
Code Injection in GitHub repository openemr/openemr prior to 7.0.1. |
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1. |
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1. |