PT-2026-28136 · Openemr · Openemr

Published

2026-03-25

·

Updated

2026-03-25

·

CVE-2026-32120

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (library/FeeSheet.class.php) allows any authenticated user with fee sheet ACL access to delete, modify, or read drug sales records belonging to arbitrary patients by manipulating the hidden prod[][sale id] form field. The save() method uses the user-supplied sale id in five SQL queries (SELECT, UPDATE, DELETE) without verifying that the record belongs to the current patient and encounter. Version 8.0.0.3 contains a patch.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-32120

Affected Products

Openemr