OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS new.php. This vulnerability is fixed in 7.0.3.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/openemr/openemr/security/advisories/GHSA-89gp-g4c9-hv8h | exploit vendor advisory |
https://github.com/openemr/openemr/commit/17c5c424695de50db94f2c01fb9abfc441d09a1a | patch |