Unrated severityNVD Advisory· Published Mar 31, 2025· Updated Mar 31, 2025
OpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability
CVE-2025-31117
Description
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to external or internal resources. this attack does not return a direct response but can be exploited through DNS or HTTP interactions to exfiltrate sensitive information. This vulnerability is fixed in 7.0.3.1.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/openemr/openemr/commit/aa6f50efb2971285633fa77ea7a50949408cab12mitrex_refsource_MISC
- github.com/openemr/openemr/security/advisories/GHSA-2pvv-ph3x-2f9hmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.