Vulnerability Description
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open-Emr | Openemr | 5.0.2.1 |
Related Weaknesses (CWE)
References
- https://blog.sonarsource.com/openemr-5-0-2-1-command-injection-vulnerability?utmExploitPatchThird Party Advisory
- https://sourceforge.net/projects/openemr/files/OpenEMR%20Current/5.0.2.1/openemrProduct
- https://www.exploit-db.com/exploits/49784ExploitThird Party AdvisoryVDB Entry
- https://www.open-emr.org/Product
- https://www.vulncheck.com/advisories/openemr-remote-code-executionThird Party Advisory
- https://www.youtube.com/watch?v=H8VWNwWgYJo&feature=emb_logoExploit
FAQ
What is CVE-2021-47817?
CVE-2021-47817 is a vulnerability with a CVSS score of 5.4 (MEDIUM). OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerabilit...
How severe is CVE-2021-47817?
CVE-2021-47817 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47817?
Check the references section above for vendor advisories and patch information. Affected products include: Open-Emr Openemr.