OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
References
Link | Resource |
---|---|
https://community.open-emr.org/t/openemr-security/10597 | Exploit Vendor Advisory |
https://www.open-emr.org/wiki/images/1/11/Openemr_insecurity.pdf | Exploit Vendor Advisory |
Configurations
Information
Published : 2020-12-30 19:15
Updated : 2021-01-05 06:45
NVD link : CVE-2018-16795
Mitre link : CVE-2018-16795
JSON object : View
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
Products Affected
open-emr
- openemr