CVE-2025-25925: XSS
Published Mar 11, 2025
·Updated
A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.
Affected Software
2 affected components
OpenMRS Openmrs
OpenMRS Openmrs=2.4.3-build0ff0ed
Event History
Mar 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25925?
CVE-2025-25925 is classified as a high-severity stored cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-25925?
To fix CVE-2025-25925, validate and sanitize input data for the personName.middleName parameter to prevent script injection.
3
What software versions are affected by CVE-2025-25925?
CVE-2025-25925 specifically affects OpenMRS v2.4.3 Build 0ff0ed.
4
What kind of attack can be executed through CVE-2025-25925?
CVE-2025-25925 allows attackers to execute arbitrary web scripts or HTML through XSS payloads.
5
Where can CVE-2025-25925 be exploited?
CVE-2025-25925 can be exploited at the /openmrs/admin/patients/shortPatientForm.form endpoint.