CVE-2025-30161

OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This vulnerability is fixed in 7.0.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

History

13 May 2025, 13:36

Type Values Removed Values Added
First Time Open-emr openemr
Open-emr
CPE cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
References () https://github.com/openemr/openemr/blob/17ca5539bafcdc25a9042ebc14480552e07867e4/interface/forms/bronchitis/view.php#L102-L103 - () https://github.com/openemr/openemr/blob/17ca5539bafcdc25a9042ebc14480552e07867e4/interface/forms/bronchitis/view.php#L102-L103 - Product
References () https://github.com/openemr/openemr/blob/17ca5539bafcdc25a9042ebc14480552e07867e4/interface/forms/bronchitis/view.php#L303-L304 - () https://github.com/openemr/openemr/blob/17ca5539bafcdc25a9042ebc14480552e07867e4/interface/forms/bronchitis/view.php#L303-L304 - Product
References () https://github.com/openemr/openemr/security/advisories/GHSA-59rv-645x-rg6p - () https://github.com/openemr/openemr/security/advisories/GHSA-59rv-645x-rg6p - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) OpenEMR es una aplicación gratuita y de código abierto para la gestión de historiales médicos electrónicos y consultas médicas. Una vulnerabilidad de XSS almacenado en el componente de formulario de bronquitis de OpenEMR permite que cualquiera que pueda editar un formulario de bronquitis robe las credenciales de los administradores. Esta vulnerabilidad se corrigió en la versión 7.0.3.

31 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-31 16:15

Updated : 2025-05-13 13:36


NVD link : CVE-2025-30161

Mitre link : CVE-2025-30161

CVE.ORG link : CVE-2025-30161


JSON object : View

Products Affected

open-emr

  • openemr
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)