CVE-2019-3967
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 29%
exploitation probability
29%top 2% of all CVEs
observed exploitation
nono source reports it
In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.
Affected products
n/a · OpenEMR