EIP-2026-110289

PRE-CVE

OpenEMR 4.1.0 - 'u' SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110289. PoCs published by Michael Ikua.

AI-analyzed exploit summary This exploit demonstrates a time-based SQL injection vulnerability in OpenEMR 4.1.0, allowing an attacker to extract usernames and password hashes from the database by leveraging the 'u' parameter in the login validation endpoint.

Description

OpenEMR 4.1.0 - 'u' SQL Injection

Exploits (1)

exploitdb WORKING POC
by Michael Ikua · pythonwebappsphp
https://www.exploit-db.com/exploits/49742

This exploit demonstrates a time-based SQL injection vulnerability in OpenEMR 4.1.0, allowing an attacker to extract usernames and password hashes from the database by leveraging the 'u' parameter in the login validation endpoint.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: OpenEMR 4.1.0
No auth needed
Prerequisites: Network access to the OpenEMR instance · The target application must be running OpenEMR 4.1.0
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026