First published: Sat Nov 04 2017(Updated: )
OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16540 is classified as a high severity vulnerability due to the potential for unauthenticated remote database copying.
To fix CVE-2017-16540, you should upgrade to OpenEMR version 5.0.0 Patch 5 or later.
CVE-2017-16540 is a remote vulnerability that allows unauthorized database access via exploited setup.php functionality.
CVE-2017-16540 affects all OpenEMR versions prior to 5.0.0 Patch 5.
The impact of CVE-2017-16540 includes the ability for attackers to clone an existing OpenEMR site to a malicious MySQL server.