CVE-2025-31121

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

History

07 May 2025, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
First Time Open-emr
Open-emr openemr
References () https://github.com/openemr/openemr/security/advisories/GHSA-2w94-qmj6-3qxx - () https://github.com/openemr/openemr/security/advisories/GHSA-2w94-qmj6-3qxx - Exploit, Vendor Advisory
Summary
  • (es) OpenEMR es una aplicación gratuita y de código abierto para la gestión de historiales médicos electrónicos y consultas médicas. En versiones anteriores a la versión 7.0.3.1, la función "Imagen del Paciente" de OpenEMR era vulnerable a ataques de cross-site scripting mediante el título EXIF de una imagen. Esta vulnerabilidad se corrigió en la versión 7.0.3.1.

01 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 15:16

Updated : 2025-05-07 15:35


NVD link : CVE-2025-31121

Mitre link : CVE-2025-31121

CVE.ORG link : CVE-2025-31121


JSON object : View

Products Affected

open-emr

  • openemr
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')