PT-2020-18655 · Openmrs · Openmrs

Published

2020-04-17

·

Updated

2020-04-23

·

CVE-2020-5732

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenMRS versions 2.9 and prior
Description The import functionality of the Data Exchange Module in OpenMRS does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.
Recommendations For OpenMRS versions 2.9 and prior, consider restricting access to the import functionality of the Data Exchange Module until a proper fix is implemented to ensure that unauthenticated users are redirected to a login page. As a temporary workaround, restrict the use of the import feature to only authenticated administrator accounts.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5732

Affected Products

Openmrs