PT-2026-26345 · Openemr · Openemr

Lassiiiiii

+2

·

Publicado

2026-03-19

·

Atualizado

2026-03-23

·

CVE-2026-33303

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 8.0.0.2
Description OpenEMR is a free and open source electronic health records and medical practice management application. The application is susceptible to a stored cross-site scripting (XSS) issue. This occurs due to unescaped portal login username within the portal credential print view. A patient portal user can inject an XSS payload as their login username, which then executes in a clinic staff member's browser when the "Create Portal Login" page is accessed for that patient. This allows for a transition from the patient session context to the staff/admin session context.
Recommendations Versions prior to 8.0.0.2 should be updated to version 8.0.0.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05091
CVE-2026-33303
GHSA-CP37-PMFX-5MHM

Produtos afetados

Openemr