Vulnerabilities
Vulnerable Software
Open-Emr:  >> Openemr  >> 7.0.1.1  Security Vulnerabilities
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This vulnerability is fixed in 7.0.3.
CVSS Score
8.4
EPSS Score
0.109
Published
2025-03-31
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS new.php. This vulnerability is fixed in 7.0.3.
CVSS Score
7.2
EPSS Score
0.003
Published
2025-03-31
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue.
CVSS Score
4.6
EPSS Score
0.008
Published
2025-03-25
An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component.
CVSS Score
3.5
EPSS Score
0.004
Published
2024-02-28


Contact Us

Shodan ® - All rights reserved