CVE-2017-9380

OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

History

09 Feb 2022, 20:45

Type Values Removed Values Added
References (MISC) https://github.com/Hacker5preme/Exploits/tree/main/CVE-2017-9380-Exploit - (MISC) https://github.com/Hacker5preme/Exploits/tree/main/CVE-2017-9380-Exploit - Exploit, Third Party Advisory
References (MISC) http://packetstormsecurity.com/files/163087/OpenEMR-5.0.0-Remote-Shell-Upload.html - (MISC) http://packetstormsecurity.com/files/163087/OpenEMR-5.0.0-Remote-Shell-Upload.html - Exploit, Third Party Advisory, VDB Entry

28 Jan 2022, 13:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/Hacker5preme/Exploits/tree/main/CVE-2017-9380-Exploit -

11 Jun 2021, 17:15

Type Values Removed Values Added
References
  • (MISC) http://packetstormsecurity.com/files/163087/OpenEMR-5.0.0-Remote-Shell-Upload.html -

Information

Published : 2017-06-02 15:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-9380

Mitre link : CVE-2017-9380

CVE.ORG link : CVE-2017-9380


JSON object : View

Products Affected

open-emr

  • openemr
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type