CVE-2022-25041
OpenEMR vulnerability analysis and mitigation

Overview

OpenEMR version 6.0.0 was discovered to contain an incorrect access control vulnerability identified as CVE-2022-25041. The vulnerability was discovered in February 2022 and affects the OpenEMR hospital information management system, which is one of the most popular open-source electronic health records and medical practice management solutions (OpenEMR GitHub, OpenEMR Website).

Technical details

The vulnerability was identified in the GET requests to '/interface/billing/customize_log.php' page. This page contains payment logs that should only be accessible to administrators. However, due to improper implementation of access controls, unauthorized users could access and view these logs (Security Everyone).

Impact

The vulnerability allows unauthorized users to access sensitive payment logs that should be restricted to administrators only. This breach of access control could potentially expose confidential financial information and violate healthcare data privacy requirements (Security Everyone).

Mitigation and workarounds

To prevent incorrect access control vulnerabilities, it is recommended to implement role-based access control (RBAC) and use access control lists (ACLs) to specify permissions for each user or group of users. Additionally, keeping all systems and software up-to-date with the latest security patches is crucial (Security Everyone).

Additional resources


SourceThis report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-22611CRITICAL9.8
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesApr 03, 2025
CVE-2013-10044HIGH8.7
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 01, 2025
CVE-2025-43860HIGH7.6
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025
CVE-2025-32794HIGH7.6
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025
CVE-2025-32967MEDIUM5.4
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management