First published: Tue Feb 07 2012(Updated: )
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0991 has a moderate severity level as it allows authenticated users to read arbitrary files.
To fix CVE-2012-0991, upgrade OpenEMR to a version higher than 4.1.0 that addresses these vulnerabilities.
CVE-2012-0991 affects users of OpenEMR version 4.1.0 with authenticated access.
The implications of CVE-2012-0991 include potential exposure of sensitive files to authenticated users.
CVE-2012-0991 impacts contrib/acog/print_form.php and multiple files in interface/patient_file/encounter.