First published: Mon Mar 22 2021(Updated: )
In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.
Credit: vulnerabilitylab@mend.io
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | >=4.2.0<=6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25922 is considered a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
To fix CVE-2021-25922, upgrade OpenEMR to version 6.0.1 or later where the vulnerability has been patched.
CVE-2021-25922 affects OpenEMR versions from 4.2.0 to 6.0.0.
CVE-2021-25922 is associated with reflected cross-site scripting (XSS) attacks.
Yes, CVE-2021-25922 can allow attackers to execute malicious code by tricking users into clicking on a malicious URL.