openmrs-module-fhir2 provides the FHIR REST API and related services for OpenMRS, an open medical records system. In versions of the FHIR2 module prior to 2.5.0, privileges were not always correctly checked, which means that unauthorized users may have been able to add or edit data they were not supposed to be able to. All implementers should update to FHIR2 2.5.0 or newer as soon as is feasible to receive a patch.
CVE ID: CVE-2025-46823
CVSS Base Severity: HIGH
CVSS Base Score: 8.0
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
Vendor: openmrs
Product: openmrs-module-fhir2
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.9% (scored less or equal to compared to others)
EPSS Date: 2025-06-07 (when was this score calculated)