Vendorsopen-emropenemr7.0.2
Vulnerabilities

open-emr Openemr 7.0.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-22611
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
Published 2025-04-03 · Analyzed
9.8EPSS 0.063
CVE-2024-37734
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
Published 2024-06-26 · Analyzed
9.8EPSS 0.008