OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.
References
| Link | Resource |
|---|---|
| https://github.com/openemr/openemr/security/advisories/GHSA-2w94-qmj6-3qxx | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-04-01 15:16
Updated : 2025-05-07 15:35
NVD link : CVE-2025-31121
Mitre link : CVE-2025-31121
CVE.ORG link : CVE-2025-31121
JSON object : View
Products Affected
open-emr
- openemr
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
