First published: Tue Aug 24 2021(Updated: )
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Tasy EMR | =3.06 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39376 is a vulnerability found in Philips Healthcare Tasy Electronic Medical Record (EMR) version 3.06, which allows SQL injection.
CVE-2021-39376 works by exploiting a SQL injection vulnerability in the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
CVE-2021-39376 has a severity rating of 8.8, which is considered high.
To fix CVE-2021-39376, it is recommended to update Philips Healthcare Tasy Electronic Medical Record (EMR) to a patched version or apply the relevant security patches provided by the vendor.
More information about CVE-2021-39376 can be found at the following reference: [link](https://diesec.home.blog/2021/08/24/philips-tasy-emr-3-06-sql-injection-cve-2021-39375cve-2021-39376/).