Medium severity6.5NVD Advisory· Published Dec 17, 2021· Updated Jun 17, 2026
CVE-2021-41843
CVE-2021-41843
Description
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- OpenEMR/OpenEMRdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/165301/OpenEMR-6.0.0-6.1.0-dev-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2021/Dec/38nvdExploitMailing ListThird Party Advisory
- trovent.github.io/security-advisories/TRSA-2109-01/TRSA-2109-01.txtnvdExploitThird Party Advisory
- trovent.io/security-advisory-2109-01nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.