漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenEMR Authenticated SQL Injection via backup.php Import Feature
Vulnerability Description
OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators with admin or super ACL privileges to execute arbitrary DDL and DML statements against the application database by uploading a crafted SQL file at the form_step=202 parameter in backup.php. Attackers can exploit the unfiltered shell_exec invocation of the mysql command-line client to extract credential hashes, modify access control tables, inject backdoor accounts, create persistent triggers or stored procedures, and write arbitrary files to the filesystem where MySQL FILE privileges and permissive secure_file_priv settings are configured.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
危险类型文件的不加限制上传
Vulnerability Title
OpenEMR 任意文件上传漏洞
Vulnerability Description
openemr是OpenEMR组织开源的一个支持文档管理与企业应用场景的医疗信息管理平台。 OpenEMR 8.2.0及之前版本存在任意文件上传漏洞,该漏洞源于备份配置导入功能中存在SQL注入,通过backup.php的form_step=202参数上传特制SQL文件,并利用未过滤的shell_exec调用mysql命令行客户端,可能导致具有admin或super ACL权限的管理员执行任意DDL和DML语句,提取凭据哈希、修改访问控制表、注入后门账户、创建持久触发器或存储过程以及写入任意文件。
CVSS Information
N/A
Vulnerability Type
N/A