First published: Fri Jul 22 2022(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2494 is a vulnerability that allows for stored cross-site scripting (XSS) attacks in the GitHub repository openemr/openemr prior to version 7.0.0.
CVE-2022-2494 has a severity rating of medium, with a CVSS score of 5.4.
The vulnerability affects openemr/openemr versions up to, but not including, version 7.0.0.
To fix CVE-2022-2494, it is recommended to update to version 7.0.0 or later of openemr/openemr.
The CWE ID for CVE-2022-2494 is CWE-79.