Vulnerabilities > Open EMR > Openemr > 2.7.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2012-09-09 | CVE-2012-2115 | SQL Injection vulnerability in Open-Emr Openemr SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the u parameter. | 7.5 |