First published: Sun May 28 2023(Updated: )
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2948 is medium (6.1).
CVE-2023-2948 is a Cross-site Scripting (XSS) vulnerability in the GitHub repository openemr/openemr prior to version 7.0.1.
CVE-2023-2948 affects the Open-emr Openemr software versions up to and excluding 7.0.1.
To fix CVE-2023-2948, update to version 7.0.1 or later of the Open-emr Openemr software.
Yes, you can find more information about CVE-2023-2948 at the following references: [GitHub Commit](https://github.com/openemr/openemr/commit/af1ecf78d1342519791bda9d3079e88f7d859015) and [Huntr.dev](https://huntr.dev/bounties/2393e4d9-9e9f-455f-bf50-f20f77b0a64d).