{"id":"CVE-2021-25922","details":"In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.","modified":"2026-03-14T10:49:28.131513Z","published":"2021-03-22T20:15:18.003Z","references":[{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25922"},{"type":"FIX","url":"https://github.com/openemr/openemr/commit/0fadc3e592d84bc9dfe9e0403f8bd6e3c7d8427f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openemr/openemr","events":[{"introduced":"6952f4a3c6938a1da938a54f58f8b86fb8a6ae50"},{"last_affected":"4c3f9f5917d765f944cdbf3b9df15375476b3711"},{"fixed":"0fadc3e592d84bc9dfe9e0403f8bd6e3c7d8427f"}],"database_specific":{"versions":[{"introduced":"4.2.0"},{"last_affected":"6.0.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25922.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}