CVE-2012-2115
09.09.2012, 21:55
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.
Vendor | Product | Version |
---|---|---|
open-emr | openemr | 𝑥 ≤ 4.1.0 |
open-emr | openemr | 3.1.0 |
open-emr | openemr | 3.2.0 |
open-emr | openemr | 4.0.0 |
𝑥
= Vulnerable software versions
References