
**CVE-2025-67752** pertains to a security flaw in **OpenEMR**, an open-source electronic health records (EHR) and practice management system. The vulnerability exists in versions prior to **7.0.4**, where the application's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`). This misconfiguration causes all external HTTPS connections to be insecure, making them susceptible to **Man-in-the-Middle (MITM)** attacks. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2025-67752
Post summary
The post announces CVE-2025-67752, a misconfiguration in OpenEMR that disables SSL/TLS certificate verification, enabling Man-in-the-Middle attacks.


