Description
|
|
A vulnerability has been discovered in OpenEMR, which can be exploited by malicious users to conduct SQL injection attacks.
Input passed via the "authProvider" POST parameter to interface/main/main_screen.php (when "auth" is set to "login" and "site" is set to "default") is not properly sanitised before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
This vulnerability is confirmed in version 4.1.1 Patch 14. Prior versions may also be affected.
|