Stored Cross-Site Scripting vulnerability in OpenEMR by OpenEMR
CVE-2021-25917
4.8MEDIUM
What is CVE-2021-25917?
OpenEMR versions 5.0.2 through 6.0.0 are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises from inadequate validation of user input, specifically within the U2F USB Device authentication method page. An attacker with high privileges could exploit this weakness to inject arbitrary scripts into input fields during the user creation process, potentially compromising sensitive data and affecting overall application integrity.
Affected Version(s)
openemr 5.0.2, 5.0.2.1, 5.0.2.2, 5.0.2.3, 5.0.2.4, 6.0.0
