First published: Thu Dec 31 2020(Updated: )
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_files.php to upload a .php file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =5.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16795 is considered a medium severity vulnerability due to its potential for exploitation through CSRF attacks.
To fix CVE-2018-16795, it is recommended to update OpenEMR to a version that addresses the CSRF vulnerability.
CVE-2018-16795 facilitates Cross-Site Request Forgery (CSRF) attacks allowing unauthorized actions.
CVE-2018-16795 specifically affects OpenEMR version 5.0.1.3.
The CVE-2018-16795 vulnerability is associated with the library/ajax and interface/super directories, particularly the manage_site_files.php file.