CVE-2018-18035: Open-EMR Openemr
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.
Affected products
- Open-EMR Openemr: before 5.0.1.6 (fixed in 5.0.1.6)
Published 2019-04-02. Last modified 2026-06-17.