PT-2026-21822 · Openemr · Openemr

Bradymiller

·

Publicado

2026-02-25

·

Atualizado

2026-02-25

·

CVE-2026-21443

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0
Description OpenEMR is an electronic health records and medical practice management application. Before version 8.0.0, the xl() translation function does not properly escape strings. The application includes wrapper functions for escaping in different contexts (xlt() for HTML, xla() for attributes, xlj() for JavaScript), but the xl() function’s output is sometimes used directly without escaping. If an attacker can inject malicious content into the translation database, this could lead to cross-site scripting (XSS). The xl() function is used to retrieve translated strings.
Recommendations Update to version 8.0.0 or later.

Exploit

Correção

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21443
GHSA-3F9J-CQJJ-7H46

Produtos afetados

Openemr