CVE-2025-54373
EUVD-2025-20641428.01.2026, 00:15
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity=high, can be viewed and changed by users who do not have Sensitivities=high privilege. Version 7.0.4 fixes the issue.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| open-emr | openemr | 7.0.3.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration