Stored Cross-Site Scripting Vulnerability in OpenEMR by OpenEMR
CVE-2021-25918

4.8MEDIUM

Key Information:

Vendor

Open-emr

Status
Vendor
CVE Published:
22 March 2021

What is CVE-2021-25918?

In OpenEMR, versions 5.0.2 through 6.0.0 are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting the TOTP Authentication method page. This occurs due to inadequate validation of user input. When creating a new user, a privileged attacker can exploit this weakness by injecting arbitrary code into the input fields, potentially leading to unauthorized actions within the application.

Affected Version(s)

openemr 5.0.2, 5.0.2.1, 5.0.2.2, 5.0.2.3, 5.0.2.4, 6.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.