Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-25919

Опубликовано: 22 мар. 2021
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Средний

Описание

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
Версия от 5.0.2 (включая) до 6.0.0 (включая)

EPSS

Процентиль: 98%
0.5897
Средний

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.

EPSS

Процентиль: 98%
0.5897
Средний

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79