PT-2020-18655 · Openmrs · Openmrs
Published
2020-04-17
·
Updated
2020-04-23
·
CVE-2020-5732
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenMRS versions 2.9 and prior
Description
The import functionality of the Data Exchange Module in OpenMRS does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.
Recommendations
For OpenMRS versions 2.9 and prior, consider restricting access to the import functionality of the Data Exchange Module until a proper fix is implemented to ensure that unauthenticated users are redirected to a login page. As a temporary workaround, restrict the use of the import feature to only authenticated administrator accounts.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openmrs