First published: Tue Aug 09 2022(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2731 is medium with a CVSS score of 6.1.
CVE-2022-2731 affects openemr/openemr prior to version 7.0.0.1, allowing for cross-site scripting (XSS) attacks.
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To fix CVE-2022-2731, users should update their openemr/openemr installations to version 7.0.0.1 or later.
More information about CVE-2022-2731 can be found in the references provided: [GitHub Commit](https://github.com/openemr/openemr/commit/285fb234bd27ea4c46a29f2797edda7f38f1d8db), [Huntr.dev](https://huntr.dev/bounties/20b8d5c5-0764-4f0b-8ab3-b9f6b857175e)