CVE-2018-15140 | OpenEMR up to 5.0.1.3 Patient Portal import_template.php docid path traversal (EDB-45202)
A vulnerability was found in OpenEMR up to 5.0.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file portal/import_template.php of the component Patient Portal. The manipulation of the argument docid as part of Directory leads to path traversal.
This vulnerability was named CVE-2018-15140. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.