Stored Cross-Site Scripting Vulnerability in Openmrs Software
CVE-2025-25925
4.8MEDIUM
What is CVE-2025-25925?
A stored cross-site scripting (XSS) vulnerability exists in Openmrs version 2.4.3 Build 0ff0ed, allowing attackers to inject malicious scripts through the personName.middleName parameter in the /openmrs/admin/patients/shortPatientForm.form endpoint. This flaw could compromise user data and facilitate unauthorized actions within the application, making it critical for organizations using this software to implement security measures to safeguard against potential exploits.
