CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.5. Its EPSS score suggests a 11.3% probability of exploitation in the next 30 days. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2012-0991
Severity
LOW
CVSS
3.5
EPSS
11.26%
Original NVD Description
Multiple directory traversal vulnerabilities in OpenEMR 4.1.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the formname parameter to (1) contrib/acog/print_form.php; or (2) load_form.php, (3) view_form.php, or (4) trend_form.php in interface/patient_file/encounter.