PT-2026-5033 · Openemr · Openemr

CVE-2025-54373

·

Publicado

2026-01-27

·

Atualizado

2026-02-12

CVSS v4.0

7.1

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.4
Description OpenEMR is an electronic health records and medical practice management application. Versions before 7.0.4 allow users without appropriate privileges to view and modify sensitive information within Clinical Notes and Care Plans when an encounter has a high sensitivity level. The Sensitivity setting determines access control to encounter data.
Recommendations Update to version 7.0.4 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-54373
GHSA-739G-6M63-P7FR

Produtos afetados

Openemr