VYPR
High severity8.8NVD Advisory· Published Jan 20, 2021· Updated Jun 17, 2026

CVE-2020-19364

CVE-2020-19364

Description

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.

Affected products

3
  • OpenEMR/OpenEMRdescription
  • Openemr/Openemr2 versions
    cpe:2.3:a:open-emr:openemr:5.0.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:open-emr:openemr:5.0.1:*:*:*:*:*:*:*
    • (no CPE)range: = 5.0.1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.