First published: Tue Aug 20 2019(Updated: )
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <=5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3968 is considered to be a critical vulnerability due to its potential for remote command execution.
To fix CVE-2019-3968, upgrade OpenEMR to version 5.0.2 or later.
Users of OpenEMR versions 5.0.1 and earlier are vulnerable to CVE-2019-3968.
CVE-2019-3968 allows authenticated attackers to execute arbitrary commands on the host system.
CVE-2019-3968 was disclosed in January 2019.