CVE-2018-15140 describes a directory traversal vulnerability in OpenEMR versions prior to 5.0.1.4, specifically within the portal/import_template.php component. An authenticated attacker in the patient portal can exploit this by manipulating the "docid" parameter when the mode is set to "get," enabling them to read arbitrary files on the system. This vulnerability carries a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring authentication but no user interaction, leading to high confidentiality impact. While not actively exploited in the wild (KEV: No), public exploit code exists on ExploitDB, demonstrating its feasibility. Despite the available exploit, there is no evidence of active exploitation, and community discussion and media coverage are minimal, suggesting low public awareness or widespread impact at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1.4CPE matchmatch criteria | cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.