CVE-2019-14530
An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.
- Affected products
- Openemr
- Open-emr Openemr
- < 5.0.2
- Fix
- Available
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 65.5% (99th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2019-08-13
CVE-2019-14530 at NVD
13 known exploits for CVE-2019-14530
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
CVE-2019-14530
exploit-CVE-2019-14530
OpenEMR 5.0.1.3 Shell Upload
OpenEMR 5.0.1.3 - (manage_site_files) Remote Code Execution (Authenticated) Exploit (2)
OpenEMR 5.0.1.3 - 'manage_site_files' Remote Code Execution (Authenticated) (2)
OpenEMR 5.0.1.7 Path Traversal
OpenEMR 5.0.1.7 - (fileName) Path Traversal (Authenticated) Exploit (2)
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated) (2)
Exploit for Path Traversal in Open-Emr Openemr
OpenEMR 5.0.1.7 - (fileName) Path Traversal (Authenticated) Exploit
OpenEMR 5.0.1.7 - 'fileName' Path Traversal (Authenticated)
OpenEMR 5.0.1.7 Path Traversal