PT-2026-24839 · Git+1 · Openemr
Pavelkohout396
·
Published
2026-03-11
·
Updated
2026-03-11
·
CVE-2026-32118
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.1
Description
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) issue exists in the Graphical Pain Map ("clickmap") form. This allows any authenticated clinician to inject arbitrary JavaScript that executes in the browser of every subsequent user who views the affected encounter form. Because session cookies are not marked HttpOnly, this enables full session hijacking of other users, including administrators. The
clickmap form is the point of injection for the malicious script. The vulnerability affects the session cookies, allowing for unauthorized access.Recommendations
Update OpenEMR to version 8.0.0.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr