CVE-2025-32967
MEDIUMDescription
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrators from auditing critical actions. This weakens traceability and opens the system to undetectable misuse by insiders or attackers. Version 7.0.3.4 contains a patch for the issue.
Is your site exposed to CVE-2025-32967?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| open-emr | openemr |
References
Frequently Asked Questions
What is CVE-2025-32967? +
How severe is CVE-2025-32967? +
What products are affected by CVE-2025-32967? +
How do I check if I'm vulnerable to CVE-2025-32967? +
Related Vulnerabilities
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: …
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent …
phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful …
Print Assumptions does not report that a definition was produced while universe checking was disabled when that definition reaches the …
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a …
HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege …