First published: Sun Sep 09 2012(Updated: )
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=4.1.0 | |
OpenEMR | =3.1.0 | |
OpenEMR | =3.2.0 | |
OpenEMR | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2115 is classified as a medium-severity SQL injection vulnerability.
To fix CVE-2012-2115, upgrade OpenEMR to version 4.1.1 or later where the vulnerability is resolved.
CVE-2012-2115 affects OpenEMR versions 4.1.0 and earlier, including versions 3.1.0 and 3.2.0.
Yes, CVE-2012-2115 can be exploited remotely to execute arbitrary SQL commands.
The vulnerable component in CVE-2012-2115 is the interface/login/validateUser.php file.