CVE-2021-47817
EUVD-2026-361821.01.2026, 18:16
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript through user profile parameters. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command execution on the vulnerable OpenEMR instance.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| open-emr | openemr | 5.0.2.1 |
𝑥
= Vulnerable software versions
References