S4E just found a medium-severity finding from asset blacklist checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 29, 2024

CVE-2019-14530 Scanner

CVE-2019-14530 scanner - Local File Inclusion (LFI) vulnerability in OpenEMR

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-14530
8.8
CVSS

An issue was discovered in custom/ajax_download.php in OpenEMR before 5.0.2 via the fileName parameter. An attacker can download any file (that is readable by the user www-data) from server storage. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from server.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

OpenEMR is a widely-used electronic medical record (EMR) and practice management software. It is designed to be a comprehensive solution for medical practices, allowing healthcare providers to manage patient records, appointments, billing, prescription and lab orders, and much more. OpenEMR is an open-source software, which means it is continuously updated by a global community of developers and made freely available to users. It is used by healthcare providers in over 200 countries and is particularly popular among small and mid-sized practices.

CVE-2019-14530 is a vulnerability that was identified in OpenEMR before version 5.0.2. This vulnerability exists in the custom/ajax_download.php file in OpenEMR, specifically in the fileName parameter. An attacker who successfully exploits this vulnerability can download any file that is readable by the user www-data - the user account under which the OpenEMR server runs. This includes sensitive patient data, financial information, and other confidential files. If the requested file is writable for the www-data user and the directory /var/www/openemr/sites/default/documents/cqm_qrda/ exists, it will be deleted from the server.

Exploitation of this vulnerability can have serious consequences for healthcare providers and their patients. Cybercriminals can gain unauthorized access to confidential patient data, billing information, and other sensitive information. They can also modify or delete medical records, which can result in serious consequences for patient care and treatment. Furthermore, successful exploitation of this vulnerability can result in financial loss for practices and/or legal consequences.

Thanks to the pro features of the s4e.io platform, healthcare providers can easily and quickly learn about vulnerabilities in their digital assets and take action to protect their practices and patients. The platform provides comprehensive and up-to-date information on vulnerabilities, along with expert guidance and support for managing and mitigating security risks. With s4e.io, healthcare providers can rest assured that they have the tools and resources they need to keep their practices and patients safe from cyber threats.

 

REFERENCES

Solution Advice

To minimize the risk of exploitation of this vulnerability, healthcare providers can take the following precautions:

  • Update to the latest version of OpenEMR (version 5.0.2 or later)
  • Restrict file permissions to prevent unauthorized access to sensitive files
  • Use a secure hosting environment for OpenEMR
  • Enforce strong authentication and access control policies
  • Regularly perform security tests and audits to ensure the system is secure

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.