Path traversal in OpenEMR - #VU142672
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to path traversal in interface/code_systems/standard_tables_manage.php and temp_dir_cleanup() when processing the db GET parameter. A remote privileged user can supply a crafted traversal sequence to delete arbitrary directories and cause a denial of service.
Exploitation through a chained attack can require tricking a superuser into visiting a crafted URL in their session context.