PT-2026-78435 · Openemr · Openemr
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.3.0
Description
A reflected cross-site scripting issue exists in the patient portal template import handler. The
templateHtml GET parameter is reflected in the page response without proper sanitization. This allows an attacker to craft a URL that executes arbitrary JavaScript in the browser of authenticated users with Forms Administration permissions, which can lead to session hijacking.Recommendations
Update to version 8.3.0 or later.
Avoid using the
templateHtml parameter in the patient portal template import handler until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr