216.73.216.6

CVE-2026-33917

· Published 26/03/2026 00:16 · Modified 26/03/2026 16:26

Labels: CVE-2026-33917 2026-03-26CVE-2026-33917CWE-89[email protected]

Essential information

Published
26/03/2026 00:16
Modified
26/03/2026 16:26
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.3 contais a SQL injection vulnerability in the ajax_save CAMOS form that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the ajax_save page in the CAMOS form. Version 8.0.0.3 patches the issue.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
open-emr / openemr cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

References