9.8

CVE-2024-37734

Exploit
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Open-emr ≫ Openemr Version 7.0.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.518
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-279 Incorrect Execution-Assigned Permissions

While it is executing, the product sets the permissions of an object in a way that violates the intended permissions that have been specified by the user.

https://github.com/A3h1nt/CVEs/tree/main/OpenEMR
Third Party Advisory
Exploit
https://github.com/openemr/openemr/pull/7435#event-12872646667
Patch
Vendor Advisory