First published: Sun May 28 2023(Updated: )
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | <7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2949 is medium.
CVE-2023-2949 affects the Open-emr Openemr software prior to version 7.0.1.
CVE-2023-2949 is associated with CWE ID 79.
To fix the Cross-site Scripting (XSS) vulnerability in Open-emr Openemr, update to version 7.0.1 or later.
More information about CVE-2023-2949 can be found at the following references: [Reference 1](https://huntr.dev/bounties/3842486f-38b1-4150-9f78-b81d0ae580c4) and [Reference 2](https://github.com/openemr/openemr/commit/af1ecf78d1342519791bda9d3079e88f7d859015).