First published: Wed Mar 30 2022(Updated: )
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <6.0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-1179.
The severity of CVE-2022-1179 is medium.
Open-emr Openemr prior to version 6.0.0.4 is affected by CVE-2022-1179.
The CWE category for CVE-2022-1179 is CWE-79 (Cross-site Scripting).
To fix the CVE-2022-1179 vulnerability, update Open-emr Openemr to version 6.0.0.4 or later.