OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
References
Link Resource
https://github.com/openemr/openemr/pull/2692 Third Party Advisory
https://github.com/openemr/openemr/pull/2698/files Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-10-05T18:39:54

Updated: 2019-10-05T18:39:54

Reserved: 2019-10-05T00:00:00


Link: CVE-2019-17197

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-10-05T19:15:11.320

Modified: 2019-10-08T15:25:19.250


Link: CVE-2019-17197

JSON object: View

cve-icon Redhat Information

No data.

CWE