PT-2019-13738 · Openemr · Openemr
Wezery
·
Publicado
2019-08-13
·
Atualizado
2022-02-10
·
CVE-2019-14530
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 5.0.2
Description
An issue was discovered in the custom/ajax download.php file via the
fileName parameter, allowing an attacker to download any file readable by the user www-data from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm qrda/ exists, it will be deleted from the server.Recommendations
For versions prior to 5.0.2, update to version 5.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the custom/ajax download.php file and the
fileName parameter to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openemr