CVE-2025-67491: 
OpenEMR vulnerability analysis and mitigation

Overview

CVE-2025-67491 is a stored cross-site scripting (XSS) vulnerability in the ub04 helper of the billing interface in OpenEMR, a widely used open-source electronic health records (EHR) and medical practice management application. It affects versions 5.0.0.5 through 7.0.3.4 and was disclosed on February 25, 2026. The vulnerability was patched in version 7.0.4. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, Feedly).

Technical details

The root cause is improper neutralization of script-related HTML tags in a web page (CWE-80 / CWE-79), located in interface/billing/ub04_helpers.php (lines 52–60). The $data variable, populated from a database query of user records, is passed via json_encode into an inline HTML click event handler enclosed in single quotes — a context where json_encode alone does not prevent XSS. An attacker with a low-privileged account (with authorized=1) can update their own fname or lname field (e.g., via interface/forms/CAMOS/rx_print.php) to a payload such as ac' ><img src=x onerror=alert(document.cookie)>, which breaks out of the single-quoted attribute context and injects arbitrary JavaScript. The fix moves attacker-controlled content out of inline onclick strings, uses OpenEMR's attr() helper for proper HTML attribute escaping, adds JSON_HEX_* flags, and delegates click handling to a safe JSON.parse() call in JavaScript context (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a low-privileged authenticated user to persistently embed malicious JavaScript in the OpenEMR billing interface, which executes in the browser of any user (including administrators) who accesses the ub04 helper endpoint. This enables session cookie theft, unauthorized actions impersonating administrators, and potential access to sensitive patient health records and medical billing data stored in the EHR system. Given OpenEMR's use in healthcare environments, exploitation could result in HIPAA-relevant data breaches and compromise of protected health information (PHI) (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly referenced in the GitHub Security Advisory, and the advisory itself documents the steps to reproduce. There is no current evidence of active in-the-wild exploitation. The EPSS score is approximately 0.165%, indicating a low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (GitHub Advisory, Feedly).

Exploitation steps

  1. Obtain a low-privileged account: Acquire or register an OpenEMR account with the authorized property set to 1 (i.e., an authorized provider account).
  2. Inject the XSS payload into a user profile field: Update the fname or lname field of the attacker's own account to a crafted payload such as ac' ><img src=x onerror=alert(document.cookie)>. This can be done via the interface/forms/CAMOS/rx_print.php endpoint or similar profile update functionality.
  3. Payload stored in database: The malicious string is stored in the users table, associated with the attacker's account.
  4. Trigger execution: When any user (including an administrator) accesses interface/billing/ub04_helpers.php, the server queries the users table and renders the attacker's name via json_encode inside a single-quoted HTML onclick attribute — the payload breaks out of the attribute context and executes in the victim's browser.
  5. Steal session cookie or perform unauthorized actions: The injected JavaScript (e.g., onerror=alert(document.cookie)) can be replaced with a payload that exfiltrates the victim's session cookie to an attacker-controlled server, enabling session hijacking and impersonation of administrators (GitHub Advisory, Vulnerable Code).

Indicators of compromise

  • Logs: Web server access logs showing requests to interface/billing/ub04_helpers.php from unusual IP addresses or at unusual times; audit logs showing modifications to fname or lname fields of user accounts containing HTML/JavaScript characters (<, >, ', onerror, img, script).
  • Database: User records in the users table where fname or lname fields contain HTML tags, JavaScript event handlers, or encoded XSS payloads.
  • Network: Outbound HTTP requests from victim browsers to external attacker-controlled domains immediately after accessing the billing interface, potentially carrying session cookie data as URL parameters or POST body.
  • Application Behavior: Unexpected JavaScript alerts, redirects, or network requests triggered when administrators or billing staff access the ub04 helper page (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenEMR to version 7.0.4 or later, which resolves the issue by moving attacker-controlled content out of inline onclick attributes, applying proper HTML attribute escaping via the attr() helper, and using JSON.parse() in a safe JavaScript context (Patch Commit). If immediate patching is not possible, restrict access to the billing interface (interface/billing/ub04_helpers.php) to trusted users only, and deploy a web application firewall (WAF) with rules to detect and block XSS payloads in user profile fields. Additionally, audit existing user records in the users table for any fname or lname values containing HTML or JavaScript content (GitHub Advisory, Feedly).

Community reactions

The vulnerability was reported by researcher codefeasto and published as a GitHub Security Advisory by OpenEMR maintainer bradymiller on February 25, 2026. Red Hat also tracked the advisory. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related OpenEMR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-40506HIGH7
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 17, 2026
CVE-2026-76614MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40509MEDIUM5.3
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40508MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026
CVE-2026-40507MEDIUM5.1
  • OpenEMR logoOpenEMR
  • cpe:2.3:a:open-emr:openemr
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management