First published: Fri May 07 2021(Updated: )
A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | =5.0.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2021-32102.
The SQL injection vulnerability exists in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.
The severity of CVE-2021-32102 is high with a severity value of 8.8.
To fix the SQL injection vulnerability in OpenEMR 5.0.2.1, you should update to a patched version of OpenEMR (e.g., OpenEMR 5.0.2 patch 5).
The CWE ID for this SQL injection vulnerability is CWE-89.