CVE-2021-39375: SQL Injection
Published Aug 24, 2021
·Updated
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.
Affected Software
1 affected component
Philips Tasy Electronic Medical Record=3.06
Event History
Aug 24, 2021
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
Description
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39375.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.'
3
What software is affected by this vulnerability?
The Philips Tasy Electronic Medical Record version 3.06 is affected by this vulnerability.
4
What is the severity of CVE-2021-39375?
CVE-2021-39375 has a severity score of 8.8 (high).
5
How does CVE-2021-39375 work?
CVE-2021-39375 allows SQL injection by manipulating the FilterValue parameter of the WAdvancedFilter/getDimensionItemsByCode endpoint in Philips Healthcare Tasy EMR 3.06.