Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before...
Vulnerability Description
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-15139
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.databreaches.net/openemr-patches-serious-vulnerabilities-uncovered-by-project-insecurity/
- https://github.com/openemr/openemr/pull/1757/commits/c2808a0493243f618bbbb3459af23c7da3dc5485
- http://packetstormsecurity.com/files/163110/OpenEMR-5.0.1.3-Shell-Upload.html
- http://packetstormsecurity.com/files/163482/OpenEMR-5.0.1.3-Shell-Upload.html
- https://github.com/Hacker5preme/Exploits/tree/main/CVE-2018-15139-Exploit
More from open-emr
View All →Affected Vendor
open-emr
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.