CVE-2018-17179: Open-EMR Openemr
Critical severity, CVSS 9.8. EPSS: 12.8% chance of exploitation in the next 30 days.
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
Affected products
- Open-EMR Openemr: before 5.0.1.7 (fixed in 5.0.1.7)
Published 2019-05-17. Last modified 2026-06-17.