← Vulnerability feed

Vulnerability record · CVE-2021-43094 · published 10 May 2022

CVE-2021-43094: Openmrs sql injection vulnerability

Openmrs · Openmrs

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

9.8 CVSS 3.1 Critical EPSS 1.3% · top 31.6% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://issues.openmrs.org/browse/TRUNK-6043 Issue TrackingThird Party AdvisoryVendor Advisory
https://openmrs.org/demo/ Product
https://wiki.openmrs.org/display/docs/Reporting+Bugs Vendor Advisory
https://issues.openmrs.org/browse/TRUNK-6043 Issue TrackingThird Party AdvisoryVendor Advisory
https://openmrs.org/demo/ Product
https://wiki.openmrs.org/display/docs/Reporting+Bugs Vendor Advisory

Track CVE-2021-43094 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-19276OpenMRS insecure XML deserialization allows unauthenticated RCEOpenMRS before 2.24.0 deserializes untrusted XML data from request bodies without adequate validation, exposing an insecure object deserialization fl…EPSS 99%analysed9.8CVE-2018-16521Openmrs html form entry xml external entity (xxe) vulnerabilityAn XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.EPSS 1.9%9.8CVE-2017-12796Openmrs deserialization of untrusted data vulnerabilityThe Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate user…EPSS 4.2%9.4CVE-2026-40076Openmrs path traversal vulnerabilityOpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module …EPSS 0.90%8.2CVE-2026-40075Openmrs path traversal vulnerabilityOpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openm…EPSS 0.72%8.0CVE-2025-25928Openmrs cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera…EPSS 0.28%7.5CVE-2022-23612Openmrs path traversal vulnerabilityOpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions…EPSS 1.9%6.8CVE-2025-25927Openmrs cross-site request forgery vulnerabilityA Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2021-43094), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.