PT-2019-9785 · Openmrs · Openmrs

Nicola Serra

·

Publicado

2019-03-17

·

Atualizado

2023-03-03

·

CVE-2018-19276

CVSS v3.1

10

Crítica

VetorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions OpenMRS versions prior to 2.24.0
Description The issue allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body. This is due to an Insecure Object Deserialization vulnerability.
Recommendations For versions prior to 2.24.0, update to version 2.24.0 or later to resolve the issue.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19276

Produtos afetados

Openmrs