漏洞描述
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.databreaches.nethttps://www.databreaches.net/openemr-patches-serious-vulnerabilities-uncovered-by-project-insecurity/↗insecurity.shhttps://insecurity.sh/reports/openemr.pdf↗github.comhttps://github.com/openemr/openemr/pull/1757↗www.open-emr.orghttps://www.open-emr.org/wiki/index.php/OpenEMR_Patches↗