Open-emr

Openemr

221 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.37%
  • Veröffentlicht 15.11.2024 11:15:09
  • Zuletzt bearbeitet 19.11.2024 16:03:56

A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient...

Exploit
  • EPSS 0.8%
  • Veröffentlicht 26.06.2024 22:15:10
  • Zuletzt bearbeitet 01.05.2025 19:38:20

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

Exploit
  • EPSS 0.41%
  • Veröffentlicht 28.02.2024 22:15:26
  • Zuletzt bearbeitet 13.05.2025 14:41:53

An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.

Exploit
  • EPSS 0.56%
  • Veröffentlicht 28.05.2023 04:15:14
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 1.47%
  • Veröffentlicht 28.05.2023 04:15:13
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 96.73%
  • Veröffentlicht 28.05.2023 04:15:12
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.49%
  • Veröffentlicht 27.05.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 90.4%
  • Veröffentlicht 27.05.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 27.05.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Code Injection in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 27.05.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.