An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CyberQuestor-infosec/CVE-2018-17179-OpenEMR
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/mynameiswillporter/Stalking-Open-Source-Offenders
- https://github.com/plzheheplztrying/cve_monitor