CVE-2018-15139
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
- Affected products
- Openemr
- Open-emr Openemr
- < 5.0.1.4
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 19.3% (97th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2018-08-13
CVE-2018-15139 at NVD
8 known exploits for CVE-2018-15139
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
exploit-CVE-2018-15139
OpenEMR 5.0.1.3 Shell Upload
OpenEMR 5.0.1.3 - (manage_site_files) Remote Code Execution (Authenticated) Exploit (2)
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
OpenEMR 5.0.1.3 Shell Upload
OpenEMR 5.0.1.3 - (manage_site_files) Remote Code Execution Exploit
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated)