Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

Code vulnerabilities put health records at risk

Blog post from Sonar

Post Details
Company
Date Published
Author
Dennis Brinkrolf
Word Count
2,053
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

The OpenEMR software, widely used for electronic health records and medical practice management, has been found to have three critical code vulnerabilities that can be combined to gain pre-auth command execution in the Patient Portal of OpenEMR 5.0.2.1 when targeting an administrator user. The vulnerabilities include a Command Injection vulnerability, a Persistent Cross-Site Scripting (XSS) vulnerability, and an Insecure API Permissions vulnerability. These vulnerabilities can lead to the compromise of sensitive patient data or critical infrastructure if exploited by a remote attacker. An OpenEMR team patch was released after the discovery of these issues, addressing the first two vulnerabilities but not the third one until version 5.0.2.2. Users hosting an OpenEMR instance are recommended to update their installation immediately to protect against potential attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.