First published: Fri May 17 2019(Updated: )
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <5.0.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17179 has a medium severity rating due to the SQL Injection vulnerability that can be exploited.
To fix CVE-2018-17179, update OpenEMR to version 5.0.1 Patch 7 or later.
CVE-2018-17179 affects OpenEMR versions prior to 5.0.1 Patch 7.
CVE-2018-17179 is classified as an SQL Injection vulnerability.
CVE-2018-17179 occurs in the make_task function located in /interface/forms/eye_mag/php/taskman_functions.php.