OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the backup functionality. Version 8.0.0.2 fixes the issue.
The vulnerability results from insufficient input validation in the backup functionality. An authenticated attacker can provide crafted data containing malicious system commands that will be executed by the application in the server context. Lack of proper filtering or escaping of input data (CWE-78) enables injection and execution of arbitrary system commands on the server side.
An attacker can gain full control over the server system, including access to confidential patient medical data, ability to modify or delete data, as well as remote code execution (RCE) with application privileges. High impact on system confidentiality, integrity and availability is confirmed by the CVSS vector.
OpenEMR should be updated immediately to version 8.0.0.2, which contains a patch eliminating the vulnerability. Detailed information is available in the manufacturer's GitHub repository (commit 7bc7bd077a624e205daed17658de41af6070ef73) and in the official security advisory GHSA-6pmc-3xm7-pm86.
OpenEMR in all versions preceding 8.0.0.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HOpen Emr Openemr
APPOpen-Emr< 8.0.0.2
Related vulnerabilities
OpenEMR: Wyciek klucza API bramki płatności do klienta w plaintext
OpenEMR: ujawnienie tokenów API MedEx bez uwierzytelnienia (Auth Bypass)
SQL Injection w OpenEMR — narażenie danych PHI przez parametr _sort
OpenEMR: path traversal umożliwia odczyt dowolnych plików przez uwierzytelnionego użytkownika
SQL Injection w OpenEMR 7.0.2 — krytyczna podatność w module aptecznym