{"id":"CVE-2021-25918","details":"In OpenEMR, versions 5.0.2 to 6.0.0 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly and rendered in the TOTP Authentication method page. A highly privileged attacker could inject arbitrary code into input fields when creating a new user.","modified":"2026-03-14T01:41:50.069320Z","published":"2021-03-22T20:15:17.753Z","references":[{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25918"},{"type":"FIX","url":"https://github.com/openemr/openemr/commit/0fadc3e592d84bc9dfe9e0403f8bd6e3c7d8427f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openemr/openemr","events":[{"introduced":"35a67d11567419866d8aa9de0ae355676eeebede"},{"last_affected":"4c3f9f5917d765f944cdbf3b9df15375476b3711"},{"fixed":"0fadc3e592d84bc9dfe9e0403f8bd6e3c7d8427f"}],"database_specific":{"versions":[{"introduced":"5.0.2"},{"last_affected":"6.0.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25918.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}