PT-2025-22807 · Openemr · Openemr

Akarsh16Reddy

·

Published

2025-05-23

·

Updated

2025-07-02

·

CVE-2025-32794

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenEMR versions prior to 7.0.3.4
Description A stored cross-site scripting (XSS) issue allows any authenticated user with patient creation privileges to inject arbitrary JavaScript code into the system by entering malicious payloads in the First and Last Name fields during patient registration. This code is later executed when viewing the patient's encounter under Orders → Procedure Orders.
Recommendations For versions prior to 7.0.3.4, update to version 7.0.3.4 to resolve the issue. As a temporary workaround, consider restricting access to the patient registration module to minimize the risk of exploitation. Avoid using the First and Last Name fields in the patient registration process until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-32794
GHSA-3C27-2M7H-F7RX

Affected Products

Openemr