CVE-2013-10044 - CVE House
Back to Database
Status published High CVE-2013-10044

OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE

Vulnerability Description

An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10044

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • xistence

Affected Vendor

OpenEMR Foundation

View all reports →

Affected Software

OpenEMR
Vulnerable Versions:
0

Timeline

Official Publish: August 1st, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)