PT-2026-28146 · Openemr · Openemr

CVE-2026-33917

·

Publicado

2026-03-25

·

Atualizado

2026-03-26

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.3
Description OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contain a SQL injection vulnerability in the ajax save CAMOS form. This issue is due to insufficient input validation in the ajax save page within the CAMOS form, and can be exploited by authenticated attackers.
Recommendations Update OpenEMR to version 8.0.0.3 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33917
GHSA-R6XQ-MFWF-WGQ8

Produtos afetados

Openemr