CVE-2022-24643
OpenEMR vulnerability analysis and mitigation

Overview

A stored cross-site scripting (XSS) vulnerability was discovered in OpenEMR Hospital Information Management System version 6.0.0. The vulnerability was identified in POST requests to /interface/new/newcomprehensivesave.php through the 'formfname' and 'formlname' parameters (Security For Everyone, CVE Mitre).

Technical details

The vulnerability exists in the POST request handling of the newcomprehensivesave.php file. Specifically, the vulnerability allows attackers to inject malicious code through the 'formfname' and 'formlname' parameters, which are not properly sanitized. This can result in stored XSS attacks where the malicious code is permanently stored on the target servers (Security For Everyone).

Impact

The vulnerability can be exploited to steal user data, such as login credentials, or to execute arbitrary actions on behalf of the user. In particular, attackers can potentially take over other user accounts through this vulnerability (Security For Everyone).

Mitigation and workarounds

To prevent XSS vulnerabilities, several measures are recommended: implement a web application firewall (WAF), perform proper input validation, implement output encoding/escaping, use contextual output encoding/escaping, implement Content Security Policy (CSP), keep all systems and software up-to-date, and use HttpOnly and Secure flags to prevent cookie theft (Security For Everyone).

Additional resources


SourceThis report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-22611CRITICAL9.8
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesApr 03, 2025
CVE-2013-10044HIGH8.7
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 01, 2025
CVE-2025-43860HIGH7.6
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025
CVE-2025-32794HIGH7.6
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025
CVE-2025-32967MEDIUM5.4
  • OpenEMROpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesMay 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management