Low severity3.5NVD Advisory· Published Feb 28, 2024· Updated Jun 17, 2026
CVE-2024-26476
CVE-2024-26476
Description
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.
Affected products
3- open-emr/open-emrdescription
Patches
Vulnerability mechanics
References
2- github.com/c4v4r0n/Research/blob/main/openemr_BlindSSRF/README.mdnvdExploitThird Party Advisory
- github.com/mpdf/mpdf/issues/867nvdIssue Tracking
News mentions
0No linked articles in our index yet.