PT-2026-28152 · Openemr · Openemr
Published
2026-03-25
·
Updated
2026-03-26
·
CVE-2026-33932
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenEMR versions prior to 8.0.0.3
Description
OpenEMR is an electronic health records and medical practice management application. A stored cross-site scripting issue exists in the CCDA document preview functionality. An attacker who can upload or send a CCDA document can execute arbitrary JavaScript in a clinician’s browser session when the document is previewed. The XSL stylesheet does not sanitize the
linkHtml attribute, allowing href="javascript:..." and event handler attributes to bypass sanitization. The vulnerable parameter is linkHtml.Recommendations
Update to version 8.0.0.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openemr