CVE-2019-14530 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in OpenEMR affects v. before 5.0.2.


OpenEMR is a widely-used electronic medical record (EMR) and practice management software. It is designed to be a comprehensive solution for medical practices, allowing healthcare providers to manage patient records, appointments, billing, prescription and lab orders, and much more. OpenEMR is an open-source software, which means it is continuously updated by a global community of developers and made freely available to users. It is used by healthcare providers in over 200 countries and is particularly popular among small and mid-sized practices.

CVE-2019-14530 is a vulnerability that was identified in OpenEMR before version 5.0.2. This vulnerability exists in the custom/ajax_download.php file in OpenEMR, specifically in the fileName parameter. An attacker who successfully exploits this vulnerability can download any file that is readable by the user www-data - the user account under which the OpenEMR server runs. This includes sensitive patient data, financial information, and other confidential files. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from the server.

Exploitation of this vulnerability can have serious consequences for healthcare providers and their patients. Cybercriminals can gain unauthorized access to confidential patient data, billing information, and other sensitive information. They can also modify or delete medical records, which can result in serious consequences for patient care and treatment. Furthermore, successful exploitation of this vulnerability can result in financial loss for practices and/or legal consequences.

