CVE-2025-30149
- EPSS 0.63%
- Veröffentlicht 31.03.2025 16:15:25
- Zuletzt bearbeitet 30.04.2025 16:08:29
OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This v...
CVE-2025-29772
- EPSS 0.68%
- Veröffentlicht 31.03.2025 16:15:24
- Zuletzt bearbeitet 13.05.2025 13:36:30
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS...
CVE-2025-29789
- EPSS 0.18%
- Veröffentlicht 25.03.2025 20:29:29
- Zuletzt bearbeitet 06.05.2025 19:26:56
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.
CVE-2024-37734
- EPSS 3.71%
- Veröffentlicht 26.06.2024 22:15:10
- Zuletzt bearbeitet 01.05.2025 19:38:20
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CVE-2012-0992
- EPSS 5.47%
- Veröffentlicht 07.02.2012 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.
CVE-2012-0991
- EPSS 40.71%
- Veröffentlicht 07.02.2012 21:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) tr...
CVE-2007-0649
- EPSS 3.72%
- Veröffentlicht 01.02.2007 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Variable overwrite vulnerability in interface/globals.php in OpenEMR 2.8.2 and earlier allows remote attackers to overwrite arbitrary program variables and conduct other unauthorized activities, such as conduct (a) remote file inclusion attacks via t...
CVE-2006-5811
- EPSS 18.59%
- Veröffentlicht 08.11.2006 23:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in library/translation.inc.php in OpenEMR 2.8.1, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[srcdir] parameter.
CVE-2006-5795
- EPSS 17.37%
- Veröffentlicht 08.11.2006 20:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple PHP remote file inclusion vulnerabilities in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the srcdir parameter to (a) billing_process.php, (b) billing_report.p...
CVE-2006-2929
- EPSS 3.09%
- Veröffentlicht 09.06.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] pa...