Vulnerabilities
CVE-2024-0875
HIGHA stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.
CVE-2024-37734
CRITICALAn issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
CVE-2023-2950
MEDIUMImproper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2949
HIGHCross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2948
HIGHCross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2946
MEDIUMImproper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2944
MEDIUMImproper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2943
MEDIUMCode Injection in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2945
MEDIUMMissing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2942
HIGHImproper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2947
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2674
HIGHImproper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2023-2566
HIGHCross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1.
CVE-2022-4733
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4615
HIGHCross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4567
HIGHImproper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4503
MEDIUMCross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4504
HIGHImproper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4506
HIGHUnrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4502
HIGHCross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4505
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-2824
HIGHAuthorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2734
CRITICALImproper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2732
HIGHMissing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2733
CRITICALCross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2731
MEDIUMCross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2729
MEDIUMCross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2730
MEDIUMAuthorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-2494
MEDIUMCross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-2493
HIGHData Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-1461
HIGHNon Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1459
HIGHNon-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1458
HIGHStored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2020-13567
HIGHMultiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2022-1179
MEDIUMNon-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1180
MEDIUMReflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1181
HIGHStored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
CVE-2022-1177
MEDIUMAccounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
CVE-2022-1178
HIGHStored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.