PT-2022-28041 · Openmrs · Openmrs Appointment Scheduling Module

Varsha5595

·

Published

2022-12-24

·

Updated

2023-01-05

·

CVE-2022-4727

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenMRS Appointment Scheduling Module versions up to 1.16.x
Description A vulnerability was found in the OpenMRS Appointment Scheduling Module, affecting the function getNotes of the file api/src/main/java/org/openmrs/module/appointmentscheduling/AppointmentRequest.java of the component Notes Handler. The manipulation of the argument notes leads to cross-site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.17.0 is able to address this issue.
Recommendations For OpenMRS Appointment Scheduling Module versions up to 1.16.x, upgrade to version 1.17.0 to address the issue. As a temporary workaround, consider restricting access to the getNotes function of the Notes Handler component until the upgrade is applied. Avoid using the notes argument in the affected component until the issue is resolved.

Fix

Improper Neutralization

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-4727

Affected Products

Openmrs Appointment Scheduling Module