CVE-2019-17197: Open-EMR Openemr
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.
Affected products
- Open-EMR Openemr: up to and including 5.0.2
Published 2019-10-05. Last modified 2026-06-17.