CVE-2025-30149
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2025-30149 is a reflected cross-site scripting (XSS) vulnerability affecting OpenEMR, a free and open-source electronic health records and medical practice management application. The issue lies in the AJAX Script interface of the super module, specifically in the layout_listitems_ajax.php file. Malicious actors could exploit this vulnerability by injecting malicious scripts through the target parameter, potentially gaining unauthorized access to user sessions or stealing sensitive data. OpenEMR has released a patch in version 7.0.3 to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenEMR
Affected Vendors
- Open-emr