Impact
The flaw allows a user with Forms Administration permissions to upload a patient portal template that contains arbitrary HTML or JavaScript. Because the input is not sanitized, the injected code is stored and later executed in the browser of any other Forms Administration user who opens the template in the HTML editor, giving the attacker the ability to steal cookies, deface the interface, or perform further client‑side attacks.
Affected Systems
OpenEMR versions earlier than 8.3.0 are vulnerable. Specifically, any release of the OpenEMR application where the patient portal template import handler is present and lacks input sanitisation. This includes all current builds prior to the 8.3.0 release.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability, and the EPSS score is not available. Because the attack requires an authenticated user with Forms Administration rights, the likelihood of exploitation is limited to environments where such permissions are granted. The vulnerability is included in the web interface of the application, so the attacker can trigger it through a browser session. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment