Stored Cross-Site Scripting in OpenEMR by OpenEMR
CVE-2025-32794

7.6HIGH

Key Information:

Vendor

Openemr

Status
Vendor
CVE Published:
23 May 2025

What is CVE-2025-32794?

OpenEMR, an open source electronic health records management application, contains a stored cross-site scripting vulnerability that affects users with permissions to create patient records. An attacker can exploit this flaw by injecting malicious JavaScript code through the First and Last Name fields during patient registration. This code is subsequently executed when accessing the patient's encounter details. The vulnerability has been addressed in version 7.0.3.4 of OpenEMR.

Affected Version(s)

openemr < 7.0.3.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-32794 : Stored Cross-Site Scripting in OpenEMR by OpenEMR