VYPR
High severity7.5NVD Advisory· Published Mar 31, 2025· Updated Jun 17, 2026

CVE-2025-31117

CVE-2025-31117

Description

OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to external or internal resources. this attack does not return a direct response but can be exploited through DNS or HTTP interactions to exfiltrate sensitive information. This vulnerability is fixed in 7.0.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Openemr/Openemr3 versions
    cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*range: <7.0.3.1
    • (no CPE)range: before 7.0.3.1
    • (no CPE)range: < 7.0.3.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.