First published: Wed Feb 22 2023(Updated: )
A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22972 is a Reflected Cross-site scripting (XSS) vulnerability in OpenEMR < 7.0.0.
CVE-2023-22972 allows remote authenticated users to inject arbitrary web script or HTML via the REQUEST_URI.
The severity of CVE-2023-22972 is medium with a CVSS score of 5.4.
To fix CVE-2023-22972 in OpenEMR, it is recommended to apply the 7.0.0 Patch released by OpenEMR.
You can find more information about CVE-2023-22972 and the 7.0.0 Patch on the OpenEMR official website.