VYPR
High severity8.8NVD Advisory· Published Feb 7, 2021· Updated Jun 17, 2026

CVE-2020-36243

CVE-2020-36243

Description

The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrary OS commands via shell metacharacters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Openemr/Openemr2 versions
    cpe:2.3:a:open-emr:openemr:5.0.2.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:open-emr:openemr:5.0.2.1:*:*:*:*:*:*:*
    • (no CPE)range: = 5.0.2.1
  • OpenEMR/OpenEMRdescription
  • Range: = 5.0.2.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.