Cross-Site Request Forgery Vulnerability in OpenEMR by OpenEMR
CVE-2018-16795
8.8HIGH
What is CVE-2018-16795?
OpenEMR version 5.0.1.3 is susceptible to Cross-Site Request Forgery (CSRF), which can be exploited through the library/ajax and interface/super functionalities. A malicious actor can leverage this weakness to upload arbitrary PHP files via the endpoint '/interface/super/manage_site_files.php', potentially compromising the security of the application and allowing unauthorized access or code execution.
