Known CVE
OpenEMR <5.0.2 - Local File Inclusion
OpenEMR before 5.0.2 is vulnerable to local file inclusion via the fileName parameter in custom/ajax_download.php. An attacker can download any file (that is readable by the web server user) from server storage. If the requested file is writable for the web server user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, the file will be deleted from server.
CVE-2019-14530
High2019CVSS 8.8CWE-22
cve2019 · lfi · authenticated · edb · openemr · open-emr · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website