Information disclosure in OpenEMR - CVE-2025-54373

 

Information disclosure in OpenEMR - CVE-2025-54373

Published: April 23, 2026


Vulnerability identifier: #VU127248
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54373
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the Clinical Notes and Care Plan forms when handling encounters marked with Sensitivity=high. A remote user can open an existing form for a restricted encounter to disclose sensitive information.

Only users without Sensitivities=high privilege are able to access the restricted form contents through these forms, while other forms mentioned in the advisory do not exhibit the same behavior.


Affected software

OpenEMR

How to mitigate CVE-2025-54373

Install security update from vendor's website.

OpenEMR - update to 7.0.4

External References

Related Security Bulletins