PT-2026-26335 · Openemr · Openemr

Lassiiiiii

·

Publicado

2026-03-19

·

Atualizado

2026-03-23

·

CVE-2026-33301

CVSS v2.0

8.5

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is an electronic health records and medical practice management application. A file read issue exists in the PDF creation function when processing form answers as unescaped HTML. This allows an attacker to include arbitrary image files from the server in generated PDFs. The issue affects users with the Notes - my encounters role who can fill Eye Exam forms in patient encounters. The vulnerability is triggered when parsing form answers, potentially leading to unauthorized access to server files. The vulnerable function processes the form answers without proper sanitization.
Recommendations Update to OpenEMR version 8.0.0.2 or later.

Exploit

Correção

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05085
CVE-2026-33301
GHSA-V9V3-Q973-XP2H

Produtos afetados

Openemr