First published: Wed Jan 20 2021(Updated: )
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19364 has a high severity rating, as it allows authenticated attackers to execute malicious PHP scripts.
To fix CVE-2020-19364, upgrade OpenEMR to a version later than 5.0.1 that addresses this vulnerability.
CVE-2020-19364 affects OpenEMR version 5.0.1, allowing script execution via a specific vulnerable endpoint.
Authenticated users with access to the OpenEMR system can exploit CVE-2020-19364 to upload malicious scripts.
Exploitation of CVE-2020-19364 can lead to unauthorized remote code execution on the affected OpenEMR instance.