
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33299 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Eye Exam form functionality, affecting all versions prior to 8.0.0.2. Authenticated users with the Notes - my encounters role can inject arbitrary JavaScript payloads into Eye Exam form fields (e.g., the HPI field), which are then executed in the browsers of any other user with the same role who views the affected patient encounter page, visit history, or printed report. The vulnerability was published on March 19, 2026, with a fix released in version 8.0.0.2. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in interface/forms/eye_mag/report.php, where form field values such as codetext, plan, and ORDER_DETAILS were echoed directly into HTML output without escaping. The fix applied in commit dccc962 wraps these outputs with OpenEMR's text() sanitization function to HTML-encode user-supplied values before rendering. An attacker with the Notes - my encounters role submits a malicious payload (e.g., <img src=x onerror=alert(document.cookie)>) into the HPI field of an Eye Exam form; the script is stored in the database and executes automatically whenever any eligible user views the encounter, visit history, or generates a print report (GitHub Advisory, Patch Commit).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of other authenticated users — including Administrators, Clinicians, and Physicians — who view the affected patient encounter or visit history. This enables session hijacking, credential theft, unauthorized actions performed on behalf of victim users (including privilege escalation by targeting administrator accounts), and exfiltration of sensitive patient health records. The stored nature of the XSS means the payload executes automatically and persistently without further attacker interaction (GitHub Advisory).
A proof-of-concept exploit with detailed step-by-step reproduction instructions and a specific payload (<img src=x onerror=alert(document.cookie)>) is publicly documented in the GitHub Security Advisory. Feedly's threat intelligence classifies the PoC confidence as high, noting nine numbered reproduction steps with precise navigation paths within the OpenEMR UI. There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.174%, reflecting low but non-zero exploitation probability (GitHub Advisory).
Notes - my encounters role (e.g., a default Clinician account).Patient > New/Search to create or select an existing patient record.Patient > Visits > Create Visit or select an existing visit.Clinical > Eye Exam.HPI > HPI field, enter a malicious XSS payload such as <img src=x onerror=alert(document.cookie)> (or a more sophisticated payload for session theft or data exfiltration).Save to persist the payload in the database.File > Print Report; the XSS fires immediately in the attacker's own browser, confirming the injection.Notes - my encounters role views the Encounter tab or navigates to Patient > Visits > Visit History and hovers over the affected form entry, the malicious script executes in their browser, enabling session hijacking or further exploitation (GitHub Advisory).document.cookie in XSS payloads)./interface/forms/eye_mag/save.php) containing HTML/JavaScript tags in form field parameters; repeated access to report.php for the same encounter by multiple users shortly after a form submission.form_eye_mag tables for fields containing <script>, onerror=, javascript:, or other HTML event handler patterns.Upgrade OpenEMR to version 8.0.0.2 or later, which escapes user-supplied form values throughout the Eye Exam report template using the text() function (Patch Commit). As a temporary workaround prior to patching, implement a strict Content Security Policy (CSP) header to restrict inline script execution, and limit the Notes - my encounters role to only highly trusted users. Administrators should also audit existing Eye Exam form entries in the database for stored malicious payloads and sanitize them manually if found (GitHub Advisory).
The vulnerability was reported by researcher lassiiiiii and remediated by kojiromike (Michael A. Smith of OpenCoreEMR Inc.), with the advisory published on March 18, 2026. The advisory notes that the same root cause — unescaped Eye Exam form output — also underlies two related advisories: GHSA-5pc3-2crw-96rv (OOB SSRF via mPDF) and GHSA-v9v3-q973-xp2h / CVE-2026-33301 (arbitrary file read via mPDF), and the single patch addresses all three vectors. Coverage was picked up by security aggregators including infinitsec.net and VulDB shortly after disclosure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."