OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
mitre·CWE-434·Published 2021-01-20