Local File Inclusion Vulnerability in OpenEMR by OpenEMR
CVE-2023-22973
8.8HIGH
What is CVE-2023-22973?
A Local File Inclusion (LFI) vulnerability exists in the OpenEMR application, specifically in the interface/forms/LBF/new.php file. This flaw allows remote authenticated users to manipulate the 'formname' parameter, potentially leading to unauthorized code execution. As a result, attackers with valid authentication can exploit this vulnerability to gain access to sensitive information or execute arbitrary commands within the affected system, posing a significant risk to the integrity and confidentiality of the application.
