PT-2025-22807 · Openemr · Openemr
Akarsh16Reddy
·
Published
2025-05-23
·
Updated
2025-07-02
·
CVE-2025-32794
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 7.0.3.4
Description
A stored cross-site scripting (XSS) issue allows any authenticated user with patient creation privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the
First and Last Name fields during patient registration. This code is later executed when viewing the patient's encounter under Orders → Procedure Orders.Recommendations
For versions prior to 7.0.3.4, update to version 7.0.3.4 to resolve the issue. As a temporary workaround, consider restricting access to the patient registration module to minimize the risk of exploitation. Avoid using the
First and Last Name fields in the patient registration process until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr