CVE-2026-40507

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page response without sanitization. An attacker can craft a URL that executes arbitrary JavaScript in the browser of any authenticated user with Forms Administration permissions who visits the link, enabling session hijacking.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 15:17

Updated : 2026-09-09 20:40


NVD link : CVE-2026-40507

Mitre link : CVE-2026-40507

CVE.ORG link : CVE-2026-40507


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')