First published: Tue Aug 20 2019(Updated: )
In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authenticated attackers to download arbitrary files from the host system.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3967 has a medium severity rating as it allows authenticated attackers to exploit a directory traversal vulnerability.
To fix CVE-2019-3967, upgrade to OpenEMR version 5.0.2 or later, which addresses this vulnerability.
Users of OpenEMR versions 5.0.1 and earlier are affected by CVE-2019-3967, particularly those with authenticated access.
CVE-2019-3967 allows attackers to download arbitrary files from the host system, which can lead to sensitive data exposure.
CVE-2019-3967 is a directory traversal vulnerability that can be exploited via the patient file download interface in OpenEMR.