First published: Fri Jun 02 2017(Updated: )
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9380 has a high severity rating as it allows low-privilege users to execute arbitrary code.
To fix CVE-2017-9380, update OpenEMR to version 5.0.1 or later to mitigate this vulnerability.
CVE-2017-9380 affects all versions of OpenEMR prior to 5.0.1.
CVE-2017-9380 allows the upload of dangerous file types that can lead to code execution.
CVE-2017-9380 can compromise system security by allowing unauthorized code execution within the vulnerable application.