PT-2020-18656 · Openmrs · Openmrs

Jimi Sebree

·

Published

2020-04-17

·

Updated

2020-04-23

·

CVE-2020-5733

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenMRS versions 2.9 and prior
Description The export functionality of the Data Exchange Module in OpenMRS does not properly redirect to a login page when an unauthenticated user attempts to access it, allowing the export of potentially sensitive information.
Recommendations For OpenMRS versions 2.9 and prior, consider restricting access to the export functionality of the Data Exchange Module until a proper fix is implemented to ensure redirection to a login page for unauthenticated users.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5733

Affected Products

Openmrs