
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33348 is a stored cross-site scripting (XSS) vulnerability in OpenEMR's Eye Exam form, specifically in the display of the $CHRONIC2 and $CHRONIC3 fields within patient encounter records. It affects all OpenEMR versions prior to 8.0.0.3 and was disclosed on March 25, 2026, with a patch released the same day. The vulnerability is classified as High severity with a CVSS v3.1 base score of 8.7 per the GitHub Security Advisory, though NVD records a score of 5.4 (Medium) (GitHub Advisory, Feedly).
The root cause is improper neutralization of user-controlled input before it is rendered in web page output (CWE-79). In interface/forms/eye_mag/report.php, the variables $CHRONIC2 and $CHRONIC3 were echoed directly into the HTML response without sanitization (e.g., echo " " . $CHRONIC2 . "";), allowing arbitrary JavaScript to be stored and later executed in victims' browsers. The fix applied the OpenEMR text() escaping function to these variables in report.php, a_issue.php, and SpectacleRx.php. Exploitation requires an authenticated attacker with the Notes - my encounters role, and the payload executes automatically when any user with the same role views the affected encounter page, prints the report, or hovers over the visit history entry (GitHub Advisory, Patch Commit).
Successful exploitation allows an authenticated attacker to inject persistent JavaScript that executes in the browsers of all users with the Notes - my encounters role who view the affected patient encounter pages, print reports, or visit history. This can lead to session hijacking, credential theft, unauthorized actions performed on behalf of higher-privileged users (e.g., administrators), and exfiltration of sensitive patient health records. In a default OpenEMR installation, affected groups include Administrators, Clinicians, and Physicians, making privilege escalation from a low-privilege clinician account to an administrator a realistic attack scenario (GitHub Advisory).
A proof-of-concept with detailed step-by-step reproduction instructions and example XSS payloads (e.g., <img src="x" onerror="alert('CHRONIC2 '+document.domain)">) is publicly available in the GitHub Security Advisory. The EPSS score is approximately 0.031% (0.000310), indicating low automated exploitation probability at this time. There is no evidence of in-the-wild exploitation or CISA KEV catalog listing as of the time of disclosure. No threat actor attribution has been reported (GitHub Advisory, Feedly).
Notes - my encounters role enabled (e.g., a default Clinicians group member such as clinician1).Patient > New/Search to select an existing patient or create a new one.Patient > Visits > Create Visit or select an existing visit via Patient > Visits > Visit History.Clinical > Eye Exam.HPI > CC1 > Chief Complaint 1 field and any value in the first Chronic Problems input.$CHRONIC2), enter a malicious payload such as <img src="x" onerror="alert('CHRONIC2 '+document.domain)">, and optionally a similar payload in the third input ($CHRONIC3).Save to persist the malicious payload in the database.File > Print Report on the encounter.Patient > Visits > Visit History under the Reason/Form column.alert() payload with a script that exfiltrates session cookies, performs CSRF actions, or escalates privileges by targeting an administrator who views the encounter (GitHub Advisory)./interface/forms/eye_mag/) containing HTML/JavaScript tags (e.g., <script>, <img, onerror=) in form field parameters.CHRONIC2 or CHRONIC3 fields contain HTML tags, JavaScript event handlers, or encoded script content.Upgrade OpenEMR to version 8.0.0.3 or later, which contains the patch applying proper HTML escaping via the text() function to the affected $CHRONIC2 and $CHRONIC3 variables in report.php, a_issue.php, and SpectacleRx.php (Patch Commit, Release Notes). As interim mitigations, restrict the Notes - my encounters role to only trusted users, implement a strict Content Security Policy (CSP) header to limit the impact of any XSS, and monitor form submissions for entries containing script tags or JavaScript event handlers (Feedly).
The vulnerability was covered by The Hacker Wire shortly after disclosure, and social media posts appeared on Mastodon and Bluesky referencing the CVE. The advisory was published by the OpenEMR project maintainers on GitHub and credited researcher lassiiiiii for the report and kojiromike for the remediation. No major vendor statements beyond the OpenEMR advisory or significant analyst commentary have been identified (The Hacker Wire, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."