PT-2026-28153 · Openemr · Openemr

Publicado

2026-03-25

·

Atualizado

2026-03-26

·

CVE-2026-33933

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions 7.0.2.1 through 8.0.0.2
Description OpenEMR is an electronic health records and medical practice management application. A reflected cross-site scripting (XSS) issue exists in the custom template editor. An attacker can execute arbitrary JavaScript in an authenticated staff member’s browser session by sending a crafted URL. The attacker does not require an OpenEMR account to exploit this. The vulnerability affects versions prior to 8.0.0.3.
Recommendations Update to version 8.0.0.3 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33933
GHSA-9QH7-CFQ4-J7C3

Produtos afetados

Openemr