Health IT Security February 2, 2023
HHS urged the healthcare sector to upgrade to the most recent version of OpenEMR to protect against three recently discovered cybersecurity vulnerabilities.
Three cybersecurity vulnerabilities in an older version of OpenEMR may leave healthcare organizations open to cyberattacks, HHS warned. HHS urged healthcare organizations using versions of OpenEMR lower than 7.0.0 to immediately apply a patch to prevent exploitation.
OpenEMR is one of the most common EHR systems, used by more than 100,000 medical providers. Software development solution company Sonar discovered the vulnerabilities and released a detailed report.
The three vulnerabilities, Unauthenticated File Read, Authenticated Local File Inclusion, and Authenticated Reflected XSS, may be used in combination by threat actors to remotely execute arbitrary system commands and...