PT-2025-31682 · Openemr · Openemr

Published

2025-08-01

·

Updated

2025-11-26

·

CVE-2013-10044

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 4.1.1 Patch 15
Description An authenticated SQL injection flaw allows a low-privileged attacker to extract administrator credentials and escalate privileges. Following privilege escalation, an unrestricted file upload flaw can be exploited to achieve remote code execution, leading to a full compromise of the application and its host system.
Recommendations Update OpenEMR to version 4.1.1 Patch 15 or later.

Exploit

Fix

RCE

Unrestricted File Upload

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2013-10044

Affected Products

Openemr