OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks against healthcare providers using OpenEMR. Version 8.0.0 fixes the issue.
History

Wed, 25 Feb 2026 02:00:00 +0000

Type Values Removed Values Added
Description OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks against healthcare providers using OpenEMR. Version 8.0.0 fixes the issue.
Title OpenEMR has Open Redirect in Eye Exam Form
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-25T01:34:35.364Z

Updated: 2026-02-25T01:34:35.364Z

Reserved: 2026-01-27T14:51:03.059Z

Link: CVE-2026-24847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-25T02:16:22.027

Modified: 2026-02-25T02:16:22.027

Link: CVE-2026-24847

cve-icon Redhat

No data.