PT-2026-24846 · Git+1 · Openemr
Pavelkohout396
·
Published
2026-03-11
·
Updated
2026-03-11
·
CVE-2026-32125
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.1
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, names associated with items in the 'Track Anything' feature are taken directly from user input (via POST requests) and displayed in Dygraph charts (titles and labels) without proper sanitization. This allows a user with the ability to create or edit 'Track Anything' items to inject malicious script that will execute when any user views the corresponding graph. The issue involves the use of
innerHTML or similar methods without escaping, leading to potential cross-site scripting (XSS). The vulnerable component is the rendering of track/item names in Dygraph charts.Recommendations
Update OpenEMR to version 8.0.0.1 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr