Open-emr

Openemr

221 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 27.05.2023 22:15:10
  • Zuletzt bearbeitet 21.11.2024 07:59:37

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 27.05.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:36

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 12.05.2023 08:15:09
  • Zuletzt bearbeitet 21.11.2024 07:59:03

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.

Exploit
  • EPSS 0.53%
  • Veröffentlicht 08.05.2023 05:15:09
  • Zuletzt bearbeitet 21.11.2024 07:58:50

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.

  • EPSS 0.43%
  • Veröffentlicht 22.02.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:44

A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.

Exploit
  • EPSS 1.81%
  • Veröffentlicht 22.02.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:44

A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via the formname parameter.

Exploit
  • EPSS 1.89%
  • Veröffentlicht 22.02.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:45:44

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 27.12.2022 15:15:12
  • Zuletzt bearbeitet 21.11.2024 07:35:50

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 19.12.2022 20:15:13
  • Zuletzt bearbeitet 21.11.2024 07:35:36

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 17.12.2022 06:15:07
  • Zuletzt bearbeitet 21.11.2024 07:35:30

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.