Vulnerabilities
Vulnerable Software
Open-Emr:  >> Openemr  >> 5.0.1.4  Security Vulnerabilities
Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
CVSS Score
6.3
EPSS Score
0.024
Published
2022-07-22
Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVSS Score
8.1
EPSS Score
0.016
Published
2022-04-25
Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVSS Score
7.3
EPSS Score
0.104
Published
2022-04-25
Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVSS Score
8.3
EPSS Score
0.005
Published
2022-04-25
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVSS Score
7.3
EPSS Score
0.245
Published
2022-03-30
Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVSS Score
4.6
EPSS Score
0.509
Published
2022-03-30
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVSS Score
4.6
EPSS Score
0.185
Published
2022-03-30
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
CVSS Score
8.0
EPSS Score
0.282
Published
2022-03-30
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
CVSS Score
6.5
EPSS Score
0.033
Published
2022-03-30
In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malicious user is aware of the first 72 characters of the victim user’s password, he can leverage it to an account takeover.
CVSS Score
8.1
EPSS Score
0.001
Published
2021-06-24


Contact Us

Shodan ® - All rights reserved