RULE(RULE ID:324145)

Rule General Information
Release Date: 2020-01-19
Rule Name: OpenEMR 5.0.0 Cross-Site Scripting Vulnerability (CVE-2018-1000020)
Severity:
CVE ID:
Rule Protection Details
Description: OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulnerability appears to have been fixed in 5.0.0 Patch 2 or higher.
Impact: An attacker could exploit this vulnerability to inject arbitrary malicious client script.
Affected OS: Windows, Linux
Reference: http://www.open-emr.org/wiki/index.php/OpenEMR_Patches
https://www.sec-consult.com/en/blog/advisories/os-command-injection-reflected-cross-site-scripting-in-openemr/index.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.open-emr.org/wiki/index.php/OpenEMR_Patches