Reflected XSS Vulnerability in OpenEMR by OpenEMR Community
CVE-2023-22972
5.4MEDIUM
What is CVE-2023-22972?
A reflected cross-site scripting vulnerability exists in OpenEMR versions prior to 7.0.0, allowing remote authenticated users to inject malicious web scripts or HTML code through the REQUEST_URI parameter. This vulnerability could potentially lead to unauthorized actions being executed on behalf of the victim, compromising the integrity and confidentiality of the application’s users.
