Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-emr openemr vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2023-2946
Improper Access Control in GitHub repository openemr/openemr before 7.0.1.
Open-emr Openemr
8.1
CVSSv3
CVE-2023-2942
Improper Input Validation in GitHub repository openemr/openemr before 7.0.1.
Open-emr Openemr
8.1
CVSSv3
CVE-2022-4567
Improper Access Control in GitHub repository openemr/openemr before 7.0.0.2.
Open-emr Openemr
8.1
CVSSv3
CVE-2022-2493
Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr before 7.0.0.
Open-emr Openemr
8.1
CVSSv3
CVE-2022-25471
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated malicious user to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.
Open-emr Openemr 6.0.0
8.1
CVSSv3
CVE-2021-25923
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
Open-emr Openemr
8.1
CVSSv3
CVE-2017-1000241
The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.
Open-emr Openemr
7.5
CVSSv3
CVE-2023-22974
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
Open-emr Openemr
1 Github repository
7.5
CVSSv3
CVE-2022-4504
Improper Input Validation in GitHub repository openemr/openemr before 7.0.0.2.
Open-emr Openemr
7.5
CVSSv3
CVE-2017-16540
OpenEMR prior to 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.
Open-emr Openemr
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »