PT-2020-18656 · Openmrs · Openmrs
Jimi Sebree
·
Published
2020-04-17
·
Updated
2020-04-23
·
CVE-2020-5733
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenMRS versions 2.9 and prior
Description
The export functionality of the Data Exchange Module in OpenMRS does not properly redirect to a login page when an unauthenticated user attempts to access it, allowing the export of potentially sensitive information.
Recommendations
For OpenMRS versions 2.9 and prior, consider restricting access to the export functionality of the Data Exchange Module until a proper fix is implemented to ensure redirection to a login page for unauthenticated users.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openmrs