CVE-2026-24848 | OpenEMR up to 7.0.4 EtherFaxActions.php disposeDocument path traversal (GHSA-5vp5-4rm6-h4c9)
A vulnerability marked as critical has been reported in OpenEMR up to 7.0.4. Affected is the function disposeDocument of the file EtherFaxActions.php. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-24848. The attack can be initiated remotely. There is not any exploit available.