CVE-2013-10044 Details
Description
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full compromise of the application and its host system.
A SQL injection vulnerability has been identified in OpenEMR versions through 4.1.1 Patch 14. This vulnerability allows a low-privileged authenticated user to inject SQL and extract sensitive information, such as administrator password hashes, from the database. Once the attacker obtains the admin password hash, they can log in as an admin user. After gaining administrative privileges, the attacker can exploit an unrestricted file upload vulnerability to upload malicious files, such as PHP scripts, which can be executed on the server, leading to a full compromise of the application and the host system.
Users are advised to upgrade to OpenEMR version 4.1.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open-emr openemr | <= 4.1.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Nov 26, 2025 | Initial Analysis | [email protected] |
| Aug 6, 2025 | CVE Modified | CISA-ADP |
| Aug 1, 2025 | New CVE Received | [email protected] |