CVE-2026-32124 | OpenEMR up to 8.0.0.1 AJAX Endpoint code_text cross site scripting (GHSA-9hw7-22mr-qhfc)
A vulnerability has been found in OpenEMR up to 8.0.0.1 and classified as problematic. Affected is an unknown function of the component AJAX Endpoint. The manipulation of the argument code_text leads to cross site scripting.
This vulnerability is documented as CVE-2026-32124. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.