Authenticated SQL Injection in OpenEMR by Lodestone Security
CVE-2019-16404
8.8HIGH
What is CVE-2019-16404?
An authenticated SQL injection vulnerability exists in OpenEMR versions up to 5.0.2, specifically in the file interface/forms/eye_mag/js/eye_base.php. This flaw enables an authenticated user to exploit the application by executing non-parameterized SQL queries, such as a potentially flawed INSERT INTO statement. By manipulating input parameters like providerID, attackers can extract arbitrary data from the underlying OpenEMR database, raising significant security concerns regarding data integrity and confidentiality.
