CVE-2017-1000241: Open-EMR Openemr

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.

Affected products

  • Open-EMR Openemr: up to and including 5.0.1

Published 2017-11-17. Last modified 2026-06-17.