S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-2733 Scanner

CVE-2022-2733 scanner - Cross-Site Scripting vulnerability in Openemr

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-2733
6.1
CVSScritical
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
openemr/openemrby openemr
AFFECTED< 7.0.0.1SAFE ✓≥ 7.0.0.1
Updated Aug 22, 2026View on NVD →
Detail

Openemr is an open-source electronic health records and medical practice management solution. It is widely used by healthcare providers for managing patient information, scheduling, billing, and prescribing. Openemr supports a diverse range of healthcare facility operations, making it a critical tool for improving patient care and operational efficiency. The platform's flexibility allows for customization to meet specific needs of clinics, hospitals, and private practices. Its widespread use underscores the importance of maintaining strong security practices to protect sensitive patient data.

CVE-2022-2733 identifies a reflected Cross-Site Scripting (XSS) vulnerability in Openemr versions prior to 7.0.0.1. This vulnerability allows attackers to inject malicious scripts into web pages, which are then executed in the context of an unsuspecting user's browser. Such vulnerabilities are exploited through crafted URLs or inputs that are not properly sanitized by the application. This can lead to various malicious activities, including session hijacking, phishing, and the theft of confidential information.

The XSS vulnerability in Openemr is triggered through the 'fee_sheet_options_ajax.php' endpoint, where the 'pricelevel' parameter is not properly sanitized, allowing the injection of HTML or script code. An attacker can exploit this by crafting a malicious URL that includes the XSS payload. When a user visits this URL, the malicious script executes within their browser, potentially compromising the session or redirecting the user to a malicious site. This flaw represents a significant risk, especially given the sensitive nature of the data managed by Openemr.

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive patient records, modification of patient data, or spreading of malware to users of the affected Openemr system. It could also erode trust in healthcare providers using the platform and result in compliance issues with regulations protecting patient health information, such as HIPAA in the United States.

S4E provides a powerful platform for detecting vulnerabilities like CVE-2022-2733 in Openemr and other critical systems. By joining our platform, healthcare providers can significantly enhance their cybersecurity posture, ensuring the confidentiality, integrity, and availability of patient data. Our comprehensive scanning solutions help identify and remediate vulnerabilities, minimizing the risk of data breaches and supporting compliance with health data protection regulations.

 

References

Solution Advice
  1. Immediately upgrade to Openemr version 7.0.0.1 or later, which contains fixes for this vulnerability.
  2. Conduct regular security audits and vulnerability scans to identify and mitigate potential security issues.
  3. Implement content security policy (CSP) headers to reduce the risk of XSS attacks.
  4. Educate users on recognizing and avoiding phishing attempts and malicious links.
  5. Ensure that all user inputs are properly sanitized both on the client and server sides to prevent injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-2733 scanner - Cross-Site Scripting vulnerability in Openemr S4E