First published: Fri Feb 09 2018(Updated: )
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command injection by an authenticated attacker with any role. This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000019 is considered a critical vulnerability due to its potential for OS command injection.
To fix CVE-2018-1000019, upgrade to OpenEMR version 5.0.0 Patch 2 or higher.
Authenticated users with any role in OpenEMR version 5.0.0 are susceptible to CVE-2018-1000019.
CVE-2018-1000019 exploits a vulnerability in fax_dispatch.php, allowing OS command injection.
Yes, CVE-2018-1000019 specifically affects OpenEMR version 5.0.0.