A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form.
Metrics
Affected Vendors & Products
References
History
Wed, 21 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openmrs
Openmrs openmrs |
|
CPEs | cpe:2.3:a:openmrs:openmrs:2.4.3:build0ff0ed:*:*:*:*:*:* | |
Vendors & Products |
Openmrs
Openmrs openmrs |
Wed, 12 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 11 Mar 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-scripting (XSS) vulnerability in Openmrs v2.4.3 Build 0ff0ed allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the personName.middleName parameter at /openmrs/admin/patients/shortPatientForm.form. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-11T00:00:00.000Z
Updated: 2025-03-12T15:23:46.471Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25925

Updated: 2025-03-12T15:23:40.910Z

Status : Analyzed
Published: 2025-03-11T20:15:16.917
Modified: 2025-05-21T19:27:00.397
Link: CVE-2025-25925

No data.