Impact
The bug resides in the Eye Exam form module prior to version 8.0.0 of OpenEMR. It allows an authenticated user to specify an arbitrary external URL that the application will redirect to, creating an open redirect condition. Attackers can leverage this to deceive users into visiting malicious or phishing sites while appearing to originate from a trusted healthcare application.
Affected Systems
Any installation of OpenEMR with a version older than 8.0.0 is vulnerable. The issue is fixed in OpenEMR 8.0.0 and later, so only users running versions 7.x or earlier are at risk.
Risk and Exploitability
The CVSS score is 6.1 indicating moderate severity. The EPSS score is less than 1 %, showing a low likelihood of public exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a logged‑in user to access the Eye Exam form and supply a malicious URL, which can be used for phishing attacks that may compromise user credentials or malicious code execution through trusted links.
OpenCVE Enrichment