top of page
perceptive_background_267k.jpg

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two pa…

Published:

2 March 2026 at 23:00:00

Alert date:

3 March 2026 at 23:01:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

OpenEMR versions 5.0.2 through 7.x.x contain a critical vulnerability where gateway_api_key secret values are rendered to clients in plaintext through at least two code paths. This information disclosure affects the payment processing functionality and could lead to arbitrary money movement or complete account takeover of payment gateway APIs. The vulnerability impacts the front_payment.php and portal_payment.php files. Organizations using OpenEMR for medical practice management should prioritize upgrading to version 8.0.0 where this issue has been resolved.

Technical details

Mitigation steps:

Affected products:

OpenEMR

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page