CVE-2018-17181: Open-EMR Openemr

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

An issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit function in /portal/lib/appsql.class.php.

Affected products

  • Open-EMR Openemr: before 5.0.1.7 (fixed in 5.0.1.7)

Published 2019-05-17. Last modified 2026-06-17.