CVE-2024-0875

MEDIUM

openemr/openemr <7.0.1 - XSS

Title source: llm
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially compromising their account. This issue is fixed in version 7.0.2.1.

Scores

CVSS v3 4.8
EPSS 0.0629
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
open-emr/openemr 7.0.1
Published Nov 15, 2024
Tracked Since Feb 18, 2026