2019-05-17 18:29:00 2019-05-20 16:03:49

An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

PARTIAL

Integrity

NONE

Availability

NONE
Open-emr Openemr 2.0.1.2 (not an official CPE) Open-emr Openemr 2.7.2 (not an official CPE) Open-emr Openemr 2.7.2 Rc1 (not an official CPE) Open-emr Openemr 2.7.2 Rc2 (not an official CPE) Open-emr Openemr 2.7.3 Rc1 (not an official CPE) Open-emr Openemr 2.8.0 (not an official CPE) Open-emr Openemr 2.8.1 (not an official CPE) Open-emr Openemr 2.8.2 (not an official CPE) Open-emr Openemr 2.8.3 (not an official CPE) Open-emr Openemr 2.9.0 (not an official CPE) Open-emr Openemr 3.0.0 (not an official CPE) Open-emr Openemr 3.0.1 (not an official CPE) open-emr OpenEMR 3.1.0 open-emr OpenEMR 3.2.0 open-emr OpenEMR 4.0.0 open-emr OpenEMR 4.1.0 open-emr OpenEMR 4.1.1 Open-emr Openemr 4.1.2 (not an official CPE) Open-emr Openemr 4.1.2.3 (not an official CPE) Open-emr Openemr 4.1.2.6 (not an official CPE) Open-emr Openemr 4.1.2.7 (not an official CPE) Open-emr Openemr 4.2.0 (not an official CPE) Open-emr Openemr 4.2.0.3 (not an official CPE) Open-emr Openemr 4.2.1 (not an official CPE) Open-emr Openemr 4.2.2 (not an official CPE) Open-emr Openemr 5.0.0 (not an official CPE) Open-emr Openemr 5.0.0.5 (not an official CPE) Open-emr Openemr 5.0.0.6 (not an official CPE) Open-emr Openemr 5.0.1 (not an official CPE) Open-emr Openemr 5.0.1.1 (not an official CPE) Open-emr Openemr 5.0.1.2 (not an official CPE) Open-emr Openemr 5.0.1.3 (not an official CPE) Open-emr Openemr 5.0.1.4 (not an official CPE) Open-emr Openemr 5.0.1.5 (not an official CPE) Open-emr Openemr 5.0.1.6 (not an official CPE)