Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-36243

The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.859
EPSS Ranking 99.3%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-36243
  • Open-Emr » Openemr » Version: 5.0.2.1
    cpe:2.3:a:open-emr:openemr:5.0.2.1


Contact Us

Shodan ® - All rights reserved