OS Command Injection & Reflected...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Vendor description: ------------------- "OpenEMR is the most popular open source electronic health records and medical practice management solution. ONC certified with international usage, OpenEMR's goal is a superior alternative to its proprietary counterparts." Source: http://www.open-emr.org/ Business recommendation: ------------------------ By exploiting the vulnerability documented in this advisory, an attacker can fully compromise the web server which has OpenEMR installed. Potentially sensitive health care and medical data might get exposed through this attack. SEC Consult recommends not to attach OpenEMR to the network until a thorough security review has been performed by security professionals and all identified issues have been resolved. Vulnerability overview/description: ----------------------------------- 1.OS Command Injection Any OS commands can be injected by an authenticated attacker with any role. This is a serious vulnerability as the chance for the system to be...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息