First published: Thu Apr 03 2025(Updated: )
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | ||
OpenEMR | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22611 is classified as a high-severity vulnerability due to its potential for SQL injection attacks.
To fix CVE-2024-22611, update OpenEMR to the latest version that addresses this SQL injection vulnerability.
CVE-2024-22611 affects files in \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php, and \openemr\controller.php.
CVE-2024-22611 can facilitate SQL injection attacks, allowing unauthorized access to the database and potential data compromise.
As of now, there is no public information indicating active exploitation of CVE-2024-22611, but it is recommended to apply patches promptly.