Security Advisory

CVE-2026-40507

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-19 14:48:49
Last updated 2026-08-21 11:20:51
Assigner VulnCheck
CVSS score 6.1
State PUBLISHED

Description

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a URL that executes arbitrary JavaScript in the browser of any authenticated user with Forms Administration permissions who visits the link, enabling session hijacking.