CVE-2026-25930
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Layout-Based Form (LBF) printable view accepts `formid` and `visitid` (or `patientid`) from the request and does not verify that the form belongs to the current user’s authorized patient/encounter. An authenticated user with LBF access can enumerate form IDs and view or print any patient’s encounter forms. Version 8.0.0 fixes the issue.
Vendor
Product
CWE
Yayın Tarihi
2026-02-25 19:43:23
Güncelleme
2026-02-27 14:38:24
Source Identifier
security-advisories@github.com
KEV Date Added
-