OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
References
| Link | Resource |
|---|---|
| https://github.com/baolqinfosec/CVE-Reseach/blob/main/OpenERM_CVE-2024-22611.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-04-03 19:15
Updated : 2025-04-08 20:21
NVD link : CVE-2024-22611
Mitre link : CVE-2024-22611
CVE.ORG link : CVE-2024-22611
JSON object : View
Products Affected
open-emr
- openemr
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
