SQL Injection Vulnerability in OpenEMR Software
CVE-2020-29140
7.2HIGH
What is CVE-2020-29140?
A vulnerability exists in OpenEMR versions before 5.0.2.5 that permits authenticated remote attackers to exploit the SQL injection flaw in the immunization report interface. By manipulating the form_code parameter, attackers can execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data within the system.
