Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.
2018-08-13T18:29:00.527
2024-11-21T03:50:23.643
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9