PT-2014-8395 · Openmrs · Openmrs

Published

2014-10-23

·

Updated

2017-09-08

·

CVE-2014-8071

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenMRS version 2.1
Description The issue allows remote attackers to inject arbitrary web script or HTML via various parameters, including givenName, familyName, address1, address2, comment, w10, HTTP Referer Header, returnUrl, and visitId in different API endpoints such as "registrationapp/registerPatient.page", "allergyui/allergy.page", "htmlformentryui/htmlform/enterHtmlForm/submit.action", "login.htm", "htmlformentryui/htmlform/enterHtmlFormWithStandardUi.page", "coreapps/mergeVisits.page", and "htmlformentryui/htmlform/enterHtmlFormWithSimpleUi.page".
Recommendations For OpenMRS version 2.1, consider disabling the parameters givenName, familyName, address1, address2, comment, w10, returnUrl, and visitId in the respective API endpoints until a patch is available. Restrict access to the affected pages to minimize the risk of exploitation. Avoid using the HTTP Referer Header in the login process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8071

Affected Products

Openmrs