Vulnerability record · CVE-2023-2948 · published 28 May 2023
CVE-2023-2948: OpenEMR cross-site scripting before 7.0.1
Open Emr · Openemr
OpenEMR versions prior to 7.0.1 contain a generic cross-site scripting (XSS) flaw (CWE-79). Because OpenEMR handles clinical and patient data, script injection in its web interface can be used to attack authenticated users of the application. The record does not specify the vulnerable parameter or page.
Description
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityPublic exploit detail and a very high EPSS score raise the likelihood of exploitation, though the flaw requires user interaction and is rated medium severity by CVSS.
What it is
OpenEMR versions prior to 7.0.1 contain a generic cross-site scripting (XSS) flaw (CWE-79). Because OpenEMR handles clinical and patient data, script injection in its web interface can be used to attack authenticated users of the application. The record does not specify the vulnerable parameter or page.
Impact
An attacker can execute script in a victim's browser session, potentially stealing session cookies or acting with the victim's privileges inside OpenEMR. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger the crafted input (UI:R), consistent with reflected or stored XSS. No authentication is needed by the attacker, though the victim is likely an authenticated OpenEMR user.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.967 probability, 99.88th percentile) and the Huntr reference is tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.
What to do
- Upgrade OpenEMR to 7.0.1 or later, applying commit af1ecf78d1342519791bda9d3079e88f7d859015.
- If immediate upgrade is not possible, restrict network exposure of the OpenEMR web interface to trusted networks or VPN.
- Deploy a WAF or input/output filtering that blocks script injection in OpenEMR request parameters.
- Set session cookies HttpOnly and Secure to reduce cookie theft impact from XSS.
- Review the Huntr advisory for the specific vulnerable endpoint and test it after patching.
Detection
- Search web/proxy logs for script tags or encoded script payloads in OpenEMR request parameters and query strings.
- Monitor for anomalous authenticated sessions, such as unexpected cookie reuse or requests from new user agents after a suspected XSS trigger.
- Alert on access to the specific endpoint named in the Huntr advisory once identified.
- Review application logs for repeated requests containing HTML/JavaScript metacharacters from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/openemr/openemr/commit/af1ecf78d1342519791bda9d3079e88f7d859015 | Patch |
| https://huntr.dev/bounties/2393e4d9-9e9f-455f-bf50-f20f77b0a64d | ExploitPatchThird Party Advisory |
| https://github.com/openemr/openemr/commit/af1ecf78d1342519791bda9d3079e88f7d859015 | Patch |
| https://huntr.dev/bounties/2393e4d9-9e9f-455f-bf50-f20f77b0a64d | ExploitPatchThird Party Advisory |
Track CVE-2023-2948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2948), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.