Reflected Cross-Site Scripting Vulnerability in OpenEMR by OpenEMR
CVE-2021-25922

6.1MEDIUM

Key Information:

Vendor

Open-emr

Status
Vendor
CVE Published:
22 March 2021

What is CVE-2021-25922?

OpenEMR versions 4.2.0 through 6.0.0 have a vulnerability related to Reflected Cross-Site Scripting (XSS). The issue stems from inadequate validation of user input, which allows an attacker to craft a malicious URL. When a user inadvertently clicks this URL, it can lead to the execution of harmful scripts in their browser session, potentially compromising sensitive information and application integrity.

Affected Version(s)

openemr 4.2.0, 4.2.0.3, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5.0.1.3, 5.0.1.4, 5.0.1.5, 5.0.1.6, 5.0.1.7, 5.0.2, 5.0.2.1, 5.0.2.2, 5.0.2.3, 5.0.2.4, 6.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.