PT-2025-13810 · Openemr · Openemr

Published

2025-03-31

·

Updated

2025-04-30

·

CVE-2025-31117

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.3.1
Description An Out-of-Band Server-Side Request Forgery (OOB SSRF) issue was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to external or internal resources. This attack does not return a direct response but can be exploited through DNS or HTTP interactions to exfiltrate sensitive information.
Recommendations For versions prior to 7.0.3.1, update to version 7.0.3.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-31117
GHSA-2PVV-PH3X-2F9H

Affected Products

Openemr