PT-2020-8564 · Openemr · Openemr
Published
2020-12-31
·
Updated
2021-01-05
·
CVE-2018-16795
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
OpenEMR version 5.0.1.3
Description:
The issue allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super. This can be demonstrated by using the interface/super/manage site files.php endpoint to upload a .php file.
Recommendations:
For OpenEMR version 5.0.1.3, consider disabling access to the interface/super/manage site files.php endpoint until a patch is available. Restrict access to the library/ajax and interface/super modules to minimize the risk of exploitation. Avoid using these modules to upload files until the issue is resolved.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr