First published: Wed Feb 22 2023(Updated: )
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22974 is a Path Traversal vulnerability in OpenEMR < 7.0.0 that allows remote unauthenticated users to read arbitrary files by controlling a connection to an attacker-controlled MySQL server.
CVE-2023-22974 affects OpenEMR versions earlier than 7.0.0.
CVE-2023-22974 has a severity rating of 7.5 (high).
Remote unauthenticated users can exploit CVE-2023-22974 by controlling a connection to an attacker-controlled MySQL server to read arbitrary files.
Yes, patches are available for CVE-2023-22974. You can find the patches at the OpenEMR official website under the 'OpenEMR Patches' section.