First published: Fri Nov 15 2024(Updated: )
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | =7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0875 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
To mitigate CVE-2024-0875, users should sanitize input fields to prevent script injection in the Secure Messaging feature.
CVE-2024-0875 affects OpenEMR version 7.0.1.
Yes, CVE-2024-0875 can potentially lead to data breaches by allowing attackers to execute malicious scripts in users' browsers.
A fix for CVE-2024-0875 should be incorporated into an updated version of OpenEMR, so upgrading to the latest version is recommended.