漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenEMR < 8.3.0 Stored XSS via Patient Portal Template Import Handler
Vulnerability Description
OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to upload template files containing arbitrary HTML or JavaScript. Attackers can inject malicious scripts through the template upload functionality, which are stored without sanitization and execute in the browser of any other Forms Administration user who views the template in the HTML editor.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
OpenEMR 跨站脚本漏洞
Vulnerability Description
openemr是OpenEMR组织开源的一个支持文档管理与企业应用场景的医疗信息管理平台。 OpenEMR 8.3.0之前版本存在跨站脚本漏洞,该漏洞源于患者门户模板导入处理程序未对上传的模板文件进行清理,可能导致存储型跨站脚本攻击,具有Forms Administration权限的已认证攻击者可上传包含任意HTML或JavaScript的模板文件,当其他表单管理用户在HTML编辑器中查看模板时,恶意脚本会在其浏览器中执行。
CVSS Information
N/A
Vulnerability Type
N/A