First published: Tue Apr 02 2019(Updated: )
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <5.0.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-18035 is considered medium due to its potential for cross-site scripting attacks.
To fix CVE-2018-18035, update OpenEMR to version 5.0.1 Patch 6 or later.
CVE-2018-18035 affects all users of OpenEMR versions before 5.0.1 Patch 6.
CVE-2018-18035 enables an unauthenticated remote attacker to perform a cross-site scripting (XSS) attack.
Yes, CVE-2018-18035 can be exploited by unauthenticated attackers, making it particularly concerning.