Files
CVEs-PoC/2018/CVE-2018-15140.md
T
2024-06-18 02:51:15 +02:00

796 B

CVE-2018-15140

Description

Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.

POC

Reference

Github

No PoCs found on GitHub currently.