CVE-2019-14530

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
6
MEDIUM
Affected
3
PROJECTS

Description

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

The most popular open source electronic health records and medical practice management solution.
GitHubGitHub
5.19K
The whole collection of Exploits developed by me (Hacker5preme)
GitHubGitHub
106
OpenEMR security issue
GitHubGitHub