Open redirect in OpenEMR - CVE-2026-24847
Published: April 23, 2026
OpenEMR
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to an arbitrary external site.
The vulnerability exists due to url redirection to an untrusted site in interface/forms/eye_mag/view.php when handling a user-supplied url parameter. A remote attacker can send a crafted link to redirect users to an arbitrary external site.
User interaction is required, and exploitation can be used in phishing attacks.