CVE-2021-41843
17.12.2021, 04:15
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.
Vendor | Product | Version |
---|---|---|
open-emr | openemr | 6.0.0 |
open-emr | openemr | 6.0.0:patch_1 |
open-emr | openemr | 6.0.0:patch_2 |
𝑥
= Vulnerable software versions
References