An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.
CVSS
No CVSS.
References
Configurations
No configuration.
History
06 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/openemr_sqli_privesc_upload.rb - | |
References | () https://www.exploit-db.com/exploits/28329 - | |
References | () https://www.exploit-db.com/exploits/28408 - |
04 Aug 2025, 15:06
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
01 Aug 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-01 21:15
Updated : 2025-08-06 15:15
NVD link : CVE-2013-10044
Mitre link : CVE-2013-10044
CVE.ORG link : CVE-2013-10044
JSON object : View
Products Affected
No product.