Suddenly no ne can login with right credentials

Situation
Hi suddenly i or my staff or Administrator can login. It doesnt say incorrect user id or password. Just it refreshes the page and shows the login screen again.

OpenEMR Version
I’m using OpenEMR version latest version and had applied 7.0.2 patch released a few days ago.

Browser:
I’m using: edge

Operating System
I’m using: linux ubuntu

Search
Did you search the forum for similar questions?

Logs
Did you check the logs?
Was there anything pertinent in them?
Please paste them here (surround with three backticks (```) for readability.
You can also turn on User Debugging under Administration->Globals->Logging User Debugging Options=>All

Apparently my server got hacked. There were a lot of login attempts form various ip’s.
The hacker made some change to the mysql.
on uploading openemr fiels the problem persisted.
but on sql restore from the backup all was good again.

Sorry to hear that, I am afarid that looks like the SQL local_infile = ON , I and my freidns we tested via kali linuex prentration testing using SQL injection and we realsed that if local_infile was on SQL injection is possbile. I hope that open emr team could find a solution towards uploading codes

Kep in mind that the test was done 5 months ago.

1 Like

I got the same situation on two different servers not too long after I applied the 7.02 patch. But luckily all the connections are being dropped.

I am thinking is it something to do with the patch.

1 Like