Sploitus

CVE-2025-67645

No indexed exploits for CVE-2025-67645 yet

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference another user’s record; the server accepts the modified IDs and applies the changes to that other user’s profile. This allows one user to alter another user’s profile data (name, contact info, etc.), and could enable account takeover. Version 7.0.4 fixes the issue.

Affected products
Openemr
Open-emr Openemr
= 7.0.3
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.3% (27th percentile)
Weakness
CWE-284
NVD status
Analyzed
Published
2026-01-27
CVE-2025-67645 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-67645 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-67645 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.