// For flags

CVE-2021-41843

OpenEMR 6.0.0 / 6.1.0-dev SQL Injection

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables of the database via the parameter provider_id, as demonstrated by the /interface/main/calendar/index.php?module=PostCalendar&func=search URI.

Un problema de inyección SQL autenticada en la función calendar search de OpenEMR versiones 6.0.0 anteriores al parche 3, permite a un atacante leer datos de todas las tablas de la base de datos por medio del parámetro provider_id, como es demostrado en el URI /interface/main/calendar/index.php?module=PostCalendar&func=search

OpenEMR versions 6.0.0 and 6.1.0-dev suffer from an authenticated remote SQL injection vulnerability in the calendar search functionality.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-10-01 CVE Reserved
  • 2021-12-15 CVE Published
  • 2024-07-11 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Open-emr
Search vendor "Open-emr"
Openemr
Search vendor "Open-emr" for product "Openemr"
6.0.0
Search vendor "Open-emr" for product "Openemr" and version "6.0.0"
-
Affected
Open-emr
Search vendor "Open-emr"
Openemr
Search vendor "Open-emr" for product "Openemr"
6.0.0
Search vendor "Open-emr" for product "Openemr" and version "6.0.0"
patch_1
Affected
Open-emr
Search vendor "Open-emr"
Openemr
Search vendor "Open-emr" for product "Openemr"
6.0.0
Search vendor "Open-emr" for product "Openemr" and version "6.0.0"
patch_2
Affected