5.5
CVSSv2

CVE-2018-15141

Published: 13/08/2018 Updated: 10/10/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

Directory traversal in portal/import_template.php in versions of OpenEMR prior to 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

open-emr openemr

Exploits

# Exploit Title: OpenEMR 5013 - Arbitrary File Actions # Date: 2018-08-14 # Exploit Author: Joshua Fam # Twitter : @Insecurity # Vendor Homepage: wwwopen-emrorg/ # Software Link: githubcom/openemr/openemr/archive/v5_0_1_3targz # Version: < 5013 # Tested on: Ubuntu LAMP, OpenEMR Version 5013 # CVE : CVE-2018-15142 ...
OpenEMR version 5013 suffers from arbitrary file read, write, and delete vulnerabilities ...