Skip to main content

OpenEMR EMR Management Vulnerabilities

Over 20 vulnerabilities in the OpenEMR open-source electronic medical record (EMR) management software have been disclosed by a security research group.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Over 20 vulnerabilities in the OpenEMR open-source electronic medical record (EMR) management software have been disclosed by a security research group.

Threat details

The vulnerabilities include SQL injection flaws, unrestricted file upload bugs, remote code execution and cross-site request forgeries. A remote attacker could exploit these vulnerabilities to access, delete or alter EMR files, upload malicious files or cause a denial-of-service condition.

For further information


Remediation steps

Type Step
OpenEMR issued an update on 15/07/2018 to address these vulnerabilities. Users and administrators are advised to apply this update immediately.

Last edited: 17 February 2020 12:51 pm