Total vulnerabilities in the database
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.
Software | From | Fixed in |
---|---|---|
open-emr / openemr | 6.0.0-patch_1 | 6.0.0-patch_1.x |
open-emr / openemr | 6.0.0-patch_2 | 6.0.0-patch_2.x |
open-emr / openemr | 6.0.0 | 6.0.0.x |