8.8
CVSSv3

CVE-2020-19364

Published: 20/01/2021 Updated: 22/01/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

OpenEMR 5.0.1 allows an authenticated malicious user to upload and execute malicious PHP scripts through /controller.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

open-emr openemr 5.0.1

Github Repositories

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious php codes.

OpenEMR Remote Code Execution Vulnerability OpenEMR 501 allows an authenticated attacker to upload and execute malicious php codes PoC git clone githubcom/EmreOvunc/OpenEMR_Vulnerabilitiesgit cd OpenEMR_Vulnerabilities python3 openemr_rce_pocpy -t 127001/openemr -u admin -p Passw0rd usage: openemr_rce_pocpy [-h]