#VU127246 Cross-site scripting in OpenEMR - CVE-2025-29772
Published: March 30, 2025 / Updated: April 23, 2026
OpenEMR
OpenEMR
Description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the CAMOS new.php page when handling the hidden_subcategory POST parameter. A remote user can send a specially crafted POST request to execute arbitrary script in a user's browser.
User interaction is required for exploitation.