Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-10044

Опубликовано: 01 авг. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
Версия до 4.1.1 (включая)

EPSS

Процентиль: 88%
0.04263
Низкий

8.8 High

CVSS3

Дефекты

CWE-89
CWE-434

Связанные уязвимости

CVSS3: 8.8
github
6 месяцев назад

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.

EPSS

Процентиль: 88%
0.04263
Низкий

8.8 High

CVSS3

Дефекты

CWE-89
CWE-434