First published: Mon Mar 31 2025(Updated: )
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This vulnerability is fixed in 7.0.3.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenEMR | <7.0.3 | |
OpenEMR | <7.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30161 is classified as a high severity stored XSS vulnerability.
To fix CVE-2025-30161, upgrade OpenEMR to version 7.0.4 or later.
CVE-2025-30161 affects users of OpenEMR versions prior to 7.0.4.
The main impact of CVE-2025-30161 is the potential for credential theft from administrators.
The Bronchitis form component of OpenEMR is vulnerable in CVE-2025-30161.