OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE
36Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 8.7epss 1.4%
da publicação à arma0 dias
Publicada no NVD1 de ago.
metasploit16 de set.
probabilidade de exploração
1.4%top 31% das CVEs
exploração observada
nãonenhuma fonte reporta
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
OpenEMR Foundation · OpenEMRReferências
https://github.com/openemr/openemrhttps://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/openemr_sqli_privesc_upload.rbhttps://www.exploit-db.com/exploits/28329https://www.exploit-db.com/exploits/28408https://www.open-emr.org/https://www.vulncheck.com/advisories/openemr-sqli-priv-esc-rce