CVE-2018-15139
Published
CVSS v3
8.8
HIGH
CVSS v2
6.5
MEDIUM
Affected
2
PROJECTS
Description
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
The most popular open source electronic health records and medical practice management solution.