JavaScript Injection Vulnerability in OpenReception Appointment Booking Software
CVE-2026-48081
8.1HIGH
What is CVE-2026-48081?
OpenReception's appointment booking software, prior to version 1.0.2, is susceptible to a JavaScript injection vulnerability. A TENANT_ADMIN could store malicious javascript: URLs in tenant configuration settings such as website, imprint, and privacyStatement. This malicious content was then returned to the patient-facing landing page, allowing the execution of unauthorized JavaScript code in the context of the patient's browser. Such behavior compromises the confidentiality of patient form data, as it can be accessed before client-side encryption is applied. With the patient-side encryption occurring only after user input, this vulnerability undermines the trust model of the application.
Affected Version(s)
appointment-booking-software < 1.0.2
