CVE-2018-15142
HIGHOpenEMR < 5.0.1.4 - Authenticated Path Traversal and Arbitrary PHP File Write via Patient Portal Import Template
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15142. PoCs published by Joshua Fam.
AI-analyzed exploit summary This exploit demonstrates arbitrary file read, write, and delete vulnerabilities in OpenEMR 5.0.1.3 via malformed POST requests to import_template.php. The PoC includes HTTP requests to read /etc/passwd, write a PHP file, and delete it.
Description
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in the traversed directory.
Exploits (1)
This exploit demonstrates arbitrary file read, write, and delete vulnerabilities in OpenEMR 5.0.1.3 via malformed POST requests to import_template.php. The PoC includes HTTP requests to read /etc/passwd, write a PHP file, and delete it.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H