CVE-2021-39376: SQL Injection
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCadF2/executaConsultaEspecifico IECORPOASSIST or CDUSUARIOCONVENIO parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39376?
CVE-2021-39376 is a vulnerability found in Philips Healthcare Tasy Electronic Medical Record (EMR) version 3.06, which allows SQL injection.
How does CVE-2021-39376 work?
CVE-2021-39376 works by exploiting a SQL injection vulnerability in the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.
What is the severity of CVE-2021-39376?
CVE-2021-39376 has a severity rating of 8.8, which is considered high.
How do I fix CVE-2021-39376?
To fix CVE-2021-39376, it is recommended to update Philips Healthcare Tasy Electronic Medical Record (EMR) to a patched version or apply the relevant security patches provided by the vendor.
Is there any additional information about CVE-2021-39376?
More information about CVE-2021-39376 can be found at the following reference: [link](https://diesec.home.blog/2021/08/24/philips-tasy-emr-3-06-sql-injection-cve-2021-39375cve-2021-39376/).