First published: Wed Jun 26 2024(Updated: )
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37734 is rated as a high severity vulnerability due to the potential for privilege escalation.
To fix CVE-2024-37734, you should upgrade OpenEMR to the latest version that resolves this issue.
OpenEMR version 7.0.2 is the affected software by CVE-2024-37734, allowing remote attackers to exploit the vulnerability.
CVE-2024-37734 can facilitate remote privilege escalation attacks via crafted POST requests.
Yes, a patch is available in subsequent releases of OpenEMR after version 7.0.2.