Back to Database
Status published
High
CVE-2012-2115
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly...
Vulnerability Description
SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2115
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2012/04/17/1
- http://www.openwall.com/lists/oss-security/2012/04/18/7
- http://www.mavitunasecurity.com/sql-injection-vulnerability-in-openemr/
- http://www.osvdb.org/78132
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71983
- http://www.exploit-db.com/exploits/18274
- http://www.securityfocus.com/bid/51247
- http://seclists.org/fulldisclosure/2012/Jan/27
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0013.html
- http://www.open-emr.org/wiki/index.php/OpenEMR_Patches
More from open-emr
View All →CVE-2022-25471
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0...
High
8.1
CVE-2022-25041
OpenEMR v6.0.0 was discovered to contain an incorrect access control...
Medium
4.3
CVE-2022-24643
A stored cross-site scripting (XSS) issue was discovered in the...
Medium
5.4
CVE-2021-41843
An authenticated SQL injection issue in the calendar search function...
Medium
6.5
CVE-2021-40352
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability...
Medium
6.5
Affected Vendor
open-emr
View all reports →Affected Software
openemr
Vulnerable Versions:
0, 3.1.0, 3.2.0, 4.0.0
Timeline
Official Publish:
September 9th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.