CVE-2022-1179: Open-EMR Openemr

Medium severity, CVSS 5.4. EPSS: 76.9% chance of exploitation in the next 30 days.

Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

Affected products

  • Open-EMR Openemr: before 6.0.0.4 (fixed in 6.0.0.4)

Published 2022-03-30. Last modified 2026-06-17.