An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.
Metrics
Affected Vendors & Products
References
History
Wed, 06 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openemr
Openemr openemr |
|
| Vendors & Products |
Openemr
Openemr openemr |
Fri, 01 Aug 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system. | |
| Title | OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE | |
| Weaknesses | CWE-434 CWE-89 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-08-01T20:46:45.592Z
Updated: 2025-08-06T14:45:03.937Z
Reserved: 2025-07-31T20:55:45.980Z
Link: CVE-2013-10044
Updated: 2025-08-06T14:44:49.221Z
Status : Awaiting Analysis
Published: 2025-08-01T21:15:26.030
Modified: 2025-08-06T15:15:29.523
Link: CVE-2013-10044
No data.
ReportizFlow