CVE-2018-15142 is a directory traversal vulnerability in OpenEMR versions prior to 5.0.1.4, specifically within the portal/import_template.php component. An authenticated attacker in the patient portal can exploit this to execute arbitrary PHP code by writing a file with a PHP extension and then accessing it in a traversed directory. With a CVSS score of 8.8 (High), this vulnerability allows for complete compromise of confidentiality, integrity, and availability. While not actively exploited in the wild or on the CISA KEV list, public exploit code exists, and it has a high FAUCET Risk Score of 92/100, indicating significant potential impact despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.1.4CPE matchmatch criteria | cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.