Vulnerabilities (CVE)

Filtered by vendor Open-emr Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13567 2 Open-emr, Phpgacl Project 2 Openemr, Phpgacl 2022-04-26 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2018-15152 1 Open-emr 1 Openemr 2022-02-10 6.4 MEDIUM 9.1 CRITICAL
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.
CVE-2019-17197 1 Open-emr 1 Openemr 2019-10-08 7.5 HIGH 9.8 CRITICAL
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
CVE-2019-14529 1 Open-emr 1 Openemr 2019-08-13 7.5 HIGH 9.8 CRITICAL
OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CVE-2018-17181 1 Open-emr 1 Openemr 2019-05-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
CVE-2018-17179 1 Open-emr 1 Openemr 2019-05-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
CVE-2018-15143 1 Open-emr 1 Openemr 2018-10-10 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.
CVE-2018-15145 1 Open-emr 1 Openemr 2018-10-10 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.