SQL Injection Vulnerability in OpenEMR by Oemr
CVE-2020-29142
7.2HIGH
What is CVE-2020-29142?
A SQL injection vulnerability exists in the OpenEMR application, specifically in the usergroup_admin.php interface. This vulnerability allows an authenticated remote attacker to execute arbitrary SQL commands through the schedule_facility parameter when the restrict_user_facility setting is turned on in the global configuration. The issue impacts OpenEMR versions prior to 5.0.2.5, putting data integrity and security at risk.
