CVE-2018-15153
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
- Affected products
- Openemr
- Open-emr Openemr
- < 5.0.1.4
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 61.6% (99th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2018-08-15
CVE-2018-15153 at NVD
No indexed exploits for CVE-2018-15153 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-15153 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.