CVE-2020-29143
EUVD-2020-2152415.02.2021, 21:15
A SQL injection vulnerability in interface/reports/non_reported.php in OpenEMR before 5.0.2.5 allows a remote authenticated attacker to execute arbitrary SQL commands via the form_code parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| open-emr | openemr | 𝑥 < 5.0.2.5 |
𝑥
= Vulnerable software versions
References