VULNERABILITY INTELLIGENCE

CVE-2012-0992

CVSS score8.5 HIGH
EPSS probability3.66%
CISA KEVNot currently listed
Published2012-02-07
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:S/C:C/I:C/A:C

Description

interface/fax/fax_dispatch.php in OpenEMR 4.1.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the file parameter.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references