CVE-2026-33911

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html` Content-Type, the browser interprets injected HTML/script tags rather than treating the output as JSON. An authenticated attacker can craft a request that executes arbitrary JavaScript in a victim's session. Version 8.0.0.3 contains a fix.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:38

Type Values Removed Values Added
Summary
  • (es) OpenEMR es una aplicación gratuita y de código abierto para registros de salud electrónicos y gestión de consultorios médicos. Antes de la versión 8.0.0.3, el parámetro POST 'title' se refleja en una respuesta JSON construida con 'json_encode()'. Debido a que la respuesta se sirve con un Content-Type 'text/html', el navegador interpreta las etiquetas HTML/script inyectadas en lugar de tratar la salida como JSON. Un atacante autenticado puede elaborar una solicitud que ejecuta JavaScript arbitrario en la sesión de una víctima. La versión 8.0.0.3 contiene una corrección.

26 Mar 2026, 16:23

Type Values Removed Values Added
References () https://github.com/openemr/openemr/commit/64e8befa0a49f85dd5e2a85c91f3f8b9e565896f - () https://github.com/openemr/openemr/commit/64e8befa0a49f85dd5e2a85c91f3f8b9e565896f - Patch
References () https://github.com/openemr/openemr/releases/tag/v8_0_0_3 - () https://github.com/openemr/openemr/releases/tag/v8_0_0_3 - Product
References () https://github.com/openemr/openemr/security/advisories/GHSA-wwhf-6cvc-6766 - () https://github.com/openemr/openemr/security/advisories/GHSA-wwhf-6cvc-6766 - Vendor Advisory
CPE cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*
First Time Open-emr openemr
Open-emr

25 Mar 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 23:17

Updated : 2026-06-17 10:38


NVD link : CVE-2026-33911

Mitre link : CVE-2026-33911

CVE.ORG link : CVE-2026-33911


JSON object : View

Products Affected

open-emr

  • openemr
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')