Vulnerability record · CVE-2022-1178 · published 30 March 2022
CVE-2022-1178: OpenEMR stored cross-site scripting before 6.0.0.4
Open Emr · Openemr
OpenEMR before 6.0.0.4 contains a stored cross-site scripting flaw (CWE-79). An attacker who can supply content that is persisted and later rendered can inject script that executes in another user's browser session. Because OpenEMR handles clinical data, script execution in a victim's session can expose or alter sensitive records.
Description
Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, but the high EPSS and public exploit reference raise the urgency for exposed OpenEMR deployments.
What it is
OpenEMR before 6.0.0.4 contains a stored cross-site scripting flaw (CWE-79). An attacker who can supply content that is persisted and later rendered can inject script that executes in another user's browser session. Because OpenEMR handles clinical data, script execution in a victim's session can expose or alter sensitive records.
Impact
An attacker can run arbitrary script in the browser of a user viewing the stored content, potentially stealing session data or acting as that user within the application. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network (AV:N) with low attack complexity (AC:L). The vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs an authenticated account and the victim must view the crafted content.
Exploitation
Not listed in CISA KEV. EPSS is high (0.51613, ~98.9th percentile), and references include an Exploit-tagged huntr bounty, indicating public exploit detail exists, though no in-the-wild activity is confirmed by this record.
What to do
- Upgrade OpenEMR to 6.0.0.4 or later, applying the referenced patch commit.
- If immediate upgrade is not possible, restrict who can create or edit the affected content and review stored input for script payloads.
- Enforce output encoding and input sanitization on stored fields, and apply a strict Content-Security-Policy to limit script execution.
- Limit exposure of the OpenEMR instance to trusted networks or require additional access controls until patched.
Detection
- Search application and web logs for stored payloads containing script tags or event handlers in user-supplied fields.
- Monitor for anomalous authenticated sessions or requests originating from users who recently viewed stored content.
- Review database records for persisted HTML/JavaScript in fields that should contain plain text.
- Alert on CSP violations or unexpected outbound requests from clinician browsers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/openemr/openemr/commit/347ad614507183035d188ba14427bc162419778c | PatchThird Party Advisory |
| https://huntr.dev/bounties/5813bd1f-b3aa-44f3-a5c0-aeeee2bf6fa4 | ExploitPatchThird Party Advisory |
| https://github.com/openemr/openemr/commit/347ad614507183035d188ba14427bc162419778c | PatchThird Party Advisory |
| https://huntr.dev/bounties/5813bd1f-b3aa-44f3-a5c0-aeeee2bf6fa4 | ExploitPatchThird Party Advisory |
Track CVE-2022-1178 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1178), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.