PT-2020-15772 · Openmrs · Openmrs Htmlformentry Module

Adam Schaal

+7

·

Published

2020-09-25

·

Updated

2020-10-05

·

CVE-2020-24621

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenMRS htmlformentry module versions prior to 3.11.0
Description A remote code execution issue was discovered, allowing a malicious Velocity Template Language file to be written to a directory through path traversal. This file could then be accessed and executed.
Recommendations For versions prior to 3.11.0, update to version 3.11.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Velocity Template Language files to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24621

Affected Products

Openmrs Htmlformentry Module