PT-2025-13810 · Openemr · Openemr
Published
2025-03-31
·
Updated
2025-04-30
·
CVE-2025-31117
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 7.0.3.1
Description
An Out-of-Band Server-Side Request Forgery (OOB SSRF) issue was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to external or internal resources. This attack does not return a direct response but can be exploited through DNS or HTTP interactions to exfiltrate sensitive information.
Recommendations
For versions prior to 7.0.3.1, update to version 7.0.3.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr