← Vulnerability feed

Vulnerability record · CVE-2023-2948 · published 28 May 2023

CVE-2023-2948: OpenEMR cross-site scripting before 7.0.1

Open Emr · Openemr

OpenEMR versions prior to 7.0.1 contain a generic cross-site scripting (XSS) flaw (CWE-79). Because OpenEMR handles clinical and patient data, script injection in its web interface can be used to attack authenticated users of the application. The record does not specify the vulnerable parameter or page.

6.1 CVSS 3.1 Medium EPSS 97% · top 0.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityPublic exploit detail and a very high EPSS score raise the likelihood of exploitation, though the flaw requires user interaction and is rated medium severity by CVSS.

What it is

OpenEMR versions prior to 7.0.1 contain a generic cross-site scripting (XSS) flaw (CWE-79). Because OpenEMR handles clinical and patient data, script injection in its web interface can be used to attack authenticated users of the application. The record does not specify the vulnerable parameter or page.

Impact

An attacker can execute script in a victim's browser session, potentially stealing session cookies or acting with the victim's privileges inside OpenEMR. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network (AV:N) with no privileges required (PR:N), but exploitation requires the victim to trigger the crafted input (UI:R), consistent with reflected or stored XSS. No authentication is needed by the attacker, though the victim is likely an authenticated OpenEMR user.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.967 probability, 99.88th percentile) and the Huntr reference is tagged Exploit, indicating public exploit detail exists. No ransomware association is documented.

What to do

  • Upgrade OpenEMR to 7.0.1 or later, applying commit af1ecf78d1342519791bda9d3079e88f7d859015.
  • If immediate upgrade is not possible, restrict network exposure of the OpenEMR web interface to trusted networks or VPN.
  • Deploy a WAF or input/output filtering that blocks script injection in OpenEMR request parameters.
  • Set session cookies HttpOnly and Secure to reduce cookie theft impact from XSS.
  • Review the Huntr advisory for the specific vulnerable endpoint and test it after patching.

Detection

  • Search web/proxy logs for script tags or encoded script payloads in OpenEMR request parameters and query strings.
  • Monitor for anomalous authenticated sessions, such as unexpected cookie reuse or requests from new user agents after a suspected XSS trigger.
  • Alert on access to the specific endpoint named in the Huntr advisory once identified.
  • Review application logs for repeated requests containing HTML/JavaScript metacharacters from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24898Open-emr openemr improper authentication vulnerabilityOpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis…EPSS 0.56%9.8CVE-2024-22611Open-emr openemr sql injection vulnerabilityOpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll…EPSS 6.3%9.8CVE-2024-37734Open-emr openemr vulnerabilityAn issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.EPSS 0.80%9.8CVE-2020-13567Open-emr openemr sql injection vulnerabilityMultiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an …EPSS 2.3%9.8CVE-2019-17197Open-emr openemr sql injection vulnerabilityOpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.EPSS 1.5%9.8CVE-2019-14529Open-emr openemr sql injection vulnerabilityOpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.EPSS 28%9.8CVE-2018-17179Open-emr openemr sql injection vulnerabilityAn issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_fun…EPSS 13%9.8CVE-2018-17181Open-emr openemr sql injection vulnerabilityAn issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-2948), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.