#VU127242 Cross-site scripting in OpenEMR - CVE-2025-31121
Published: April 1, 2025 / Updated: April 23, 2026
OpenEMR
OpenEMR
Description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the Patient Image feature when rendering user-supplied image-related content. A remote privileged user can inject a crafted payload to execute arbitrary script in a user's browser.
User interaction is required for exploitation.