PT-2020-8564 · Openemr · Openemr

Published

2020-12-31

·

Updated

2021-01-05

·

CVE-2018-16795

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OpenEMR version 5.0.1.3
Description: The issue allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super. This can be demonstrated by using the interface/super/manage site files.php endpoint to upload a .php file.
Recommendations: For OpenEMR version 5.0.1.3, consider disabling access to the interface/super/manage site files.php endpoint until a patch is available. Restrict access to the library/ajax and interface/super modules to minimize the risk of exploitation. Avoid using these modules to upload files until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16795

Affected Products

Openemr