Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfgc-hxhc-jhc4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

EPSS

Процентиль: 1%
0.00012
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract arbitrary data from the openemr database via a non-parameterized INSERT INTO statement, as demonstrated by the providerID parameter.

EPSS

Процентиль: 1%
0.00012
Низкий