Stored Cross-Site Scripting vulnerability in OpenEMR by OpenEMR
CVE-2021-25917

4.8MEDIUM

Key Information:

Vendor

Open-emr

Status
Vendor
CVE Published:
22 March 2021

What is CVE-2021-25917?

OpenEMR versions 5.0.2 through 6.0.0 are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises from inadequate validation of user input, specifically within the U2F USB Device authentication method page. An attacker with high privileges could exploit this weakness to inject arbitrary scripts into input fields during the user creation process, potentially compromising sensitive data and affecting overall application integrity.

Affected Version(s)

openemr 5.0.2, 5.0.2.1, 5.0.2.2, 5.0.2.3, 5.0.2.4, 6.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.