Brady Miller
56 exploits
Active since Aug 2017
OpenEMR < 5.0.1.7 - SQL Injection via taskman.php
CVSS 9.8
OpenEMR < 8.0.0 - Authenticated SQL Injection in Prescription Listing
CVSS 8.8
OpenEMR < 8.0.0 - Authenticated SQL Injection in Prescription Listing
CVSS 8.8
OpenEMR 5.0.2-7.9.9 - Info Disclosure
CVSS 9.6
OpenEMR 5.0.0.5-7.0.3.4 - Stored Cross-Site Scripting in Billing UB04 Helper
CVSS 5.4
OpenEMR 5.0.2-7.9.9 - Info Disclosure
CVSS 9.6
Reflected XSS via Unescaped contextName Parameter in Custom Template Editor
CVSS 6.1
OpenEMR's Message Update Ignores Patient id
CVSS 6.5
OpenEMR < 8.0.0 - Authenticated Authorization Bypass via Patient Portal Signature Endpoint
CVSS 8.1
OpenEMR 5.0.0.5-7.0.3.4 - Stored Cross-Site Scripting in Billing UB04 Helper
CVSS 5.4
OpenEMR <8.0.0 - Broken Access Control
CVSS 6.5
OpenEMR <8.0.0 - Privilege Escalation
CVSS 6.5
OpenEMR <8.0.0 - Privilege Escalation
CVSS 8.8
OpenEMR 5.0.0 and prior - Improper Encoding or Escaping of Output in csv_log_html Function
CVSS 7.5
OpenEMR < 5.0.1 - Reflected Cross-Site Scripting via Multiple Parameters
CVSS 6.1
OpenEMR < 5.0.1 - Authenticated Access Control Bypass via Letter Template Parameters
CVSS 6.5
OpenEMR < 5.0.1 - Authenticated Access Control Bypass via Fax Dispatch Scan Parameter
CVSS 8.8
OpenEMR < 5.0.1.7 - Path Traversal via docid Parameter in download_template.php
CVSS 5.3
OpenEMR < 5.0.1.7 - SQL Injection via SaveAudit and portalAudit Functions
CVSS 9.8
OpenEMR < 5.0.1.1 - Authenticated SQL Injection via newlistname Parameter
CVSS 8.8
OpenEMR 5.0.2-6.0.0 - Stored Cross-Site Scripting in U2F USB Device Authentication Page
CVSS 4.8
OpenEMR 5.0.2-6.0.0 - Stored Cross-Site Scripting in TOTP Authentication Method Page
CVSS 4.8
OpenEMR 5.0.2-6.0.0 - Stored Cross-Site Scripting in User Input Fields
CVSS 4.8
OpenEMR <6.0.0 - Privilege Escalation
CVSS 6.5
OpenEMR 2.7.3-6.0.0 - Stored Cross-Site Scripting in Allergies Section
CVSS 5.4