PT-2025-14119 · Openemr · Openemr

Published

2025-04-01

·

Updated

2025-04-02

·

CVE-2025-31121

CVSS v4.0

7.0

High

VectorAV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.3.1
Description The Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image.
Recommendations For versions prior to 7.0.3.1, update to version 7.0.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the Patient Image feature until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-31121
GHSA-2W94-QMJ6-3QXX

Affected Products

Openemr