PT-2014-8395 · Openmrs · Openmrs
Published
2014-10-23
·
Updated
2017-09-08
·
CVE-2014-8071
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenMRS version 2.1
Description
The issue allows remote attackers to inject arbitrary web script or HTML via various parameters, including
givenName, familyName, address1, address2, comment, w10, HTTP Referer Header, returnUrl, and visitId in different API endpoints such as "registrationapp/registerPatient.page", "allergyui/allergy.page", "htmlformentryui/htmlform/enterHtmlForm/submit.action", "login.htm", "htmlformentryui/htmlform/enterHtmlFormWithStandardUi.page", "coreapps/mergeVisits.page", and "htmlformentryui/htmlform/enterHtmlFormWithSimpleUi.page".Recommendations
For OpenMRS version 2.1, consider disabling the parameters
givenName, familyName, address1, address2, comment, w10, returnUrl, and visitId in the respective API endpoints until a patch is available. Restrict access to the affected pages to minimize the risk of exploitation. Avoid using the HTTP Referer Header in the login process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openmrs