CVE-2026-25746
HIGHOpenEMR < 8.0.0 - Authenticated SQL Injection in Prescription Listing
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2026-25746. PoCs published by XiaomingX, ChrisSub08.
AI-analyzed exploit summary The repository contains a functional exploit for CVE-2026-25746, demonstrating a SQL injection vulnerability in OpenEMR <8.0.0 via the 'sort' parameter in the prescription listing functionality. The exploit includes a Python script that performs boolean-based SQL injection to extract data from the database.
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0 contain a SQL injection vulnerability in prescription that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the prescription listing functionality. Version 8.0.0 fixes the vulnerability.
Exploits (2)
The repository contains a functional exploit for CVE-2026-25746, demonstrating a SQL injection vulnerability in OpenEMR <8.0.0 via the 'sort' parameter in the prescription listing functionality. The exploit includes a Python script that performs boolean-based SQL injection to extract data from the database.
The repository contains a functional exploit for CVE-2026-25746, demonstrating a SQL injection vulnerability in OpenEMR <8.0.0 via the 'sort' parameter in the prescription listing functionality. The exploit includes a Python script that performs boolean-based SQL injection to extract data from the database.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H