Vulnerabilities
Vulnerable Software
Open-Emr:  >> Openemr  >> 5.0.1.4  Security Vulnerabilities
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
CVSS Score
9.8
EPSS Score
0.014
Published
2019-05-17
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
CVSS Score
6.1
EPSS Score
0.012
Published
2019-04-02
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
CVSS Score
5.4
EPSS Score
0.008
Published
2018-08-20
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that can result in The vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.. This attack appear to be exploitable via The victim must visit on a specially crafted URL..
CVSS Score
5.4
EPSS Score
0.009
Published
2018-08-20


Contact Us

Shodan ® - All rights reserved