openemr是OpenEMR组织开源的一个支持文档管理与企业应用场景的医疗信息管理平台。 OpenEMR 8.2.0及之前版本存在代码注入漏洞,该漏洞源于document category tree组件中的eval()调用未经过清理,可能导致认证管理员通过注入PHP有效载荷执行任意操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-67610 | 8.1 HIGH | OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access |
| CVE-2026-67611 | 8.1 HIGH | OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration |
| CVE-2026-39931 | 7.2 HIGH | OpenEMR Authenticated SQL Injection via backup.php Import Feature |
| CVE-2026-67612 | 4.8 MEDIUM | OpenEMR 8.2.0 Stored XSS via import_template.php Template Management |
No comments yet