CVE-2025-54373
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity=high, can be viewed and changed by users who do not have Sensitivities=high privilege.
Version 7.0.4 fixes the issue.
MEDIUM · CVSS 6.5
EPSS 0.00038
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0