CVE-2026-24908 | OpenEMR up to 7.x REST API Endpoint _sort sql injection (GHSA-rcc2-45v3-qmqm)
A vulnerability was found in OpenEMR up to 7.x. It has been declared as critical. This affects an unknown function of the component REST API Endpoint. The manipulation of the argument _sort results in sql injection.
This vulnerability is known as CVE-2026-24908. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.