OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the patient selection feature. Version 8.0.0.3 contains a patch.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the patient selection feature. Version 8.0.0.3 contains a patch. | |
| Title | OpenEMR has a SQL Injection Vulnerability in patient selection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-25T22:41:02.472Z
Reserved: 2026-03-24T15:41:47.491Z
Link: CVE-2026-33910
No data.
Status : Received
Published: 2026-03-25T23:17:10.173
Modified: 2026-03-25T23:17:10.173
Link: CVE-2026-33910
No data.
OpenCVE Enrichment
No data.