VYPR
Medium severity6.1OSV Advisory· Published Apr 2, 2019· Updated Jun 17, 2026

CVE-2018-18035

CVE-2018-18035

Description

A vulnerability in flashcanvas.swf in OpenEMR before 5.0.1 Patch 6 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Openemr/OpenemrOSV3 versions
    v2_7_2, v2_7_2-rc1, v2_7_2-rc2, …+ 2 more
    • (no CPE)range: v2_7_2, v2_7_2-rc1, v2_7_2-rc2, …
    • cpe:2.3:a:open-emr:openemr:*:*:*:*:*:*:*:*range: <5.0.1.6
    • (no CPE)range: <5.0.1 Patch 6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.