First published: Tue Aug 01 2017(Updated: )
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12064 is considered a medium severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2017-12064, update OpenEMR to version 5.0.1 or later where the vulnerability is addressed.
CVE-2017-12064 affects users running OpenEMR version 5.0.0 or earlier.
The attack vector for CVE-2017-12064 involves bypassing intended access restrictions by using a crafted name in the csv_log_html function.
The vulnerable component in CVE-2017-12064 is the csv_log_html function located in library/edihistory/edih_csv_inc.php.