OpenEMR.C_DocumentCategory.class.php.Stored.XSS
Description
This indicates an attack attempt to exploit a Cross-Site Scripting Vulnerability in OpenEMR Development Team OpenEMR.
The vulnerability is due to insufficient sanitization of user input in Document Categories page. A remote, authenticated attacker can exploit this vulnerability by sending crafted requests to the target server. Successful exploitation of this vulnerability could result in arbitrary script execution in the target user's browser.
Affected Products
OpenEMR Development Team OpenEMR prior to 6.0.0.4
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://github.com/openemr/openemr/commit/347ad614507183035d188ba14427bc162419778c
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |