OpenEMR EMR Management Vulnerabilities
Over 20 vulnerabilities in the OpenEMR open-source electronic medical record (EMR) management software have been disclosed by a security research group.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Over 20 vulnerabilities in the OpenEMR open-source electronic medical record (EMR) management software have been disclosed by a security research group.
Threat details
The vulnerabilities include SQL injection flaws, unrestricted file upload bugs, remote code execution and cross-site request forgeries. A remote attacker could exploit these vulnerabilities to access, delete or alter EMR files, upload malicious files or cause a denial-of-service condition.
For further information
Remediation steps
| Type | Step |
|---|---|
|
OpenEMR issued an update on 15/07/2018 to address these vulnerabilities. Users and administrators are advised to apply this update immediately. |
Last edited: 17 February 2020 12:51 pm