CVE-2018-15142 | OpenEMR up to 5.0.1.3 Patient Portal import_template.php docid/content path traversal (EDB-45202)
A vulnerability classified as critical has been found in OpenEMR up to 5.0.1.3. Affected is an unknown function of the file portal/import_template.php of the component Patient Portal. The manipulation of the argument docid/content leads to path traversal.
This vulnerability is traded as CVE-2018-15142. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.