Openemr
by Openemr
Source repositories
CVEs (229)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2731 | Med | 0.00 | 6.1 | 0.01 | Aug 9, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2730 | Med | 0.00 | 6.5 | 0.01 | Aug 9, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2729 | Med | 0.00 | 5.4 | 0.01 | Aug 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1. | ||
| CVE-2022-2494 | Med | 0.00 | 5.4 | 0.01 | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0. | ||
| CVE-2022-2493 | Hig | 0.00 | 8.1 | 0.01 | Jul 22, 2022 | Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0. | ||
| CVE-2022-1461 | Med | 0.00 | 6.5 | 0.01 | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1459 | Hig | 0.00 | 8.3 | 0.01 | Apr 25, 2022 | Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1458 | Med | 0.00 | 5.4 | 0.01 | Apr 25, 2022 | Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. | ||
| CVE-2022-1180 | Low | 0.00 | 3.5 | 0.01 | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. | ||
| CVE-2021-25923 | Hig | 0.00 | 8.1 | 0.01 | Jun 24, 2021 | In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover. | ||
| CVE-2021-25922 | Med | 0.00 | 6.1 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code. | ||
| CVE-2021-25920 | Med | 0.00 | 6.5 | 0.01 | Mar 22, 2021 | In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user. | ||
| CVE-2021-25918 | Med | 0.00 | 4.8 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a… | ||
| CVE-2021-25917 | Med | 0.00 | 4.8 | 0.01 | Mar 22, 2021 | In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when… | ||
| CVE-2019-17197 | Cri | 0.00 | 9.8 | 0.01 | Oct 5, 2019 | OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc. | ||
| CVE-2018-17181 | Cri | 0.00 | 9.8 | 0.01 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php. | ||
| CVE-2018-17180 | Med | 0.00 | 5.3 | 0.02 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php. | ||
| CVE-2018-15151 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter. | ||
| CVE-2018-15150 | Hig | 0.00 | 8.8 | 0.02 | Aug 15, 2018 | SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in… |
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 6.5epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.
- risk 0.00cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
- risk 0.00cvss 8.1epss 0.01
Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.
- risk 0.00cvss 6.5epss 0.01
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 8.3epss 0.01
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 5.4epss 0.01
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
- risk 0.00cvss 3.5epss 0.01
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- risk 0.00cvss 8.1epss 0.01
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
- risk 0.00cvss 6.1epss 0.01
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.
- risk 0.00cvss 6.5epss 0.01
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.
- risk 0.00cvss 4.8epss 0.01
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a…
- risk 0.00cvss 4.8epss 0.01
In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the U2F USB Device authentication method page. A highly privileged attacker could inject arbitrary code into input fields when…
- risk 0.00cvss 9.8epss 0.01
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
- risk 0.00cvss 9.8epss 0.01
An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.
- risk 0.00cvss 5.3epss 0.02
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'search_term' parameter.
- risk 0.00cvss 8.8epss 0.02
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the 'temporary_files_dir' variable in…
Page 11 of 12