6.5
CVSSv3

CVE-2021-41843

Published: 17/12/2021 Updated: 22/12/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N

Vulnerability Summary

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an malicious user to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

open-emr openemr 6.0.0

Exploits

OpenEMR versions 600 and 610-dev suffer from an authenticated remote SQL injection vulnerability in the calendar search functionality ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Trovent Security Advisory 2109-01 / CVE-2021-41843: Authenticated SQL injection in OpenEMR calendar search <!--X-Subje ...