CVE-2017-9380
HIGHOpenEMR < 5.0.0 - Authenticated Arbitrary File Upload and Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-9380. PoCs published by Ron Jost.
AI-analyzed exploit summary This exploit demonstrates an authenticated remote code execution vulnerability in OpenEMR 5.0.0 by uploading a malicious file through the patient registration feature. The exploit authenticates, creates a random patient, and prepares to upload a file, though the actual file upload and execution payload is truncated.
Description
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.
Exploits (1)
This exploit demonstrates an authenticated remote code execution vulnerability in OpenEMR 5.0.0 by uploading a malicious file through the patient registration feature. The exploit authenticates, creates a random patient, and prepares to upload a file, though the actual file upload and execution payload is truncated.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H