SQL Injection Vulnerability in Philips Healthcare Tasy EMR 3.06 via WAdvancedFilter/getDimensionItemsByCode FilterValue Parameter

SQL Injection Vulnerability in Philips Healthcare Tasy EMR 3.06 via WAdvancedFilter/getDimensionItemsByCode FilterValue Parameter

CVE-2021-39375 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.