Tag
high
advisory
Remote Code Execution in OpenEMR Document Category Tree
8 TTPs 1 CVEOpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.
OpenEMR +1
web-application-vulnerability
remote-code-execution
healthcare
cve-2026-39931
sql-injection
web-application
vulnerability
authentication-bypass
+1
8t
1c
critical
advisory
FHIR Validator SSRF via /loadIG Leads to Credential Theft
2 rules 2 TTPs 1 IOCThe FHIR Validator HTTP service is vulnerable to server-side request forgery (SSRF) via the `/loadIG` endpoint, enabling attackers to steal authentication tokens by exploiting a prefix-matching flaw in the credential provider.
FHIR Validator
ssrf
fhir
credential-theft
vulnerability
2r
2t
1i