CVE-2025-30149

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 79

Summary

CVE-2025-30149 is a reflected cross-site scripting (XSS) vulnerability affecting OpenEMR, a free and open-source electronic health records and medical practice management application. The issue lies in the AJAX Script interface of the super module, specifically in the layout_listitems_ajax.php file. Malicious actors could exploit this vulnerability by injecting malicious scripts through the target parameter, potentially gaining unauthorized access to user sessions or stealing sensitive data. OpenEMR has released a patch in version 7.0.3 to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share