First published: Sat Oct 05 2019(Updated: )
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17197 is classified as a medium severity SQL Injection vulnerability.
To fix CVE-2019-17197, update OpenEMR to a version later than 5.0.2 that addresses the SQL injection issue.
OpenEMR versions up to and including 5.0.2 are affected by CVE-2019-17197.
CVE-2019-17197 facilitates SQL Injection attacks through the Lifestyle demographic filter criteria.
CVE-2019-17197 involves the library/clinical_rules.php and library/patient.inc files.