First published: Tue Aug 24 2021(Updated: )
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Tasy Electronic Medical Record | =3.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-39375.
The title of the vulnerability is 'Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.'
The Philips Tasy Electronic Medical Record version 3.06 is affected by this vulnerability.
CVE-2021-39375 has a severity score of 8.8 (high).
CVE-2021-39375 allows SQL injection by manipulating the FilterValue parameter of the WAdvancedFilter/getDimensionItemsByCode endpoint in Philips Healthcare Tasy EMR 3.06.