CVE-2024-26476 - OpenEMR Blind SSRF via HTML Injection in PDF Generator (mPDF) Key Information CVE ID: CVE-2024-26476 Vulnerable Product: OpenEMR Vulnerable Version: < 7.0.2 Description: OpenEMR has a blind Server-Side Request Forgery (SSRF) vulnerability via HTML injection in the PDF generator (mPDF). Details Input Sanitization Issue: There is no input sanitization in the PDF content generated in . Attack Vector Authenticated User: An authenticated user can request the with a XSS payload in the parameter to inject an img tag with a src attribute pointing to a server controlled by the attacker. Example URL: Reported By Vinicius Silva on 02/13/2024 Fixed In Commit: https://github.com/openemr/openemr/commit/846301aaa798839025cfb3cf3d58dbfda1e4e5ba Additional Links NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-26476 Product: https://www.open-emr.org/