SQL Injection Vulnerability in OpenEMR Affects Multiple Versions
CVE-2026-33917
8.8HIGH
What is CVE-2026-33917?
OpenEMR, an open-source electronic health records and medical practice management application, has a vulnerability due to inadequate input validation in the ajax_save functionality of the CAMOS form. This SQL injection flaw can be exploited by authenticated attackers to manipulate database queries. It is crucial to upgrade to version 8.0.0.3 or later, which addresses this security issue.
Affected Version(s)
openemr < 8.0.0.3
