Записи OpenMRS
31 опубликованных записей вендора openmrs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,2 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 29 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
31 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2018-19276Готовый эксплойт | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitraopenmrs · openmrs · CWE-502 | Критическая9,8 | — | 98,7 % | 21 мар. 2019 г. |
40В плане | CVE-2017-12796Эксплойта нет | The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authentiopenmrs · openmrs · CWE-502 | Критическая9,8 | — | 4,2 % | 23 окт. 2017 г. |
40В плане | CVE-2017-12795Эксплойта нет | OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).openmrs · openmrs-module-htmlformentry · CWE-20 | Критическая9,8 | — | 2,3 % | 10 мая 2019 г. |
40В плане | CVE-2018-16521Эксплойта нет | An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.openmrs · html form entry · CWE-611 | Критическая9,8 | — | 1,9 % | 5 сент. 2018 г. |
39Наблюдать | CVE-2021-43094Эксплойта нет | An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 viaopenmrs · openmrs · CWE-89 | Критическая9,8 | — | 1,3 % | 10 мая 2022 г. |
37Наблюдать | CVE-2026-40076Эксплойта нет | OpenMRS Core arbitrary file write and code execution via Zip Slip in module uploadopenmrs · openmrs · CWE-22 | Критическая9,4 | — | 0,9 % | 6 мая 2026 г. |
36Наблюдать | CVE-2020-24621Эксплойта нет | A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.openmrs · htmlformentry · CWE-22 | Высокая8,8 | — | 3,2 % | 25 сент. 2020 г. |
35Наблюдать | CVE-2017-7990Эксплойта нет | The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insertopenmrs · openmrs module reporting · CWE-352 | Высокая8,8 | — | 1,1 % | 20 апр. 2017 г. |
32Наблюдать | CVE-2026-40075Эксплойта нет | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs · openmrs · CWE-22 | Высокая8,2 | — | 0,7 % | 5 мая 2026 г. |
32Наблюдать | CVE-2025-25928Эксплойта нет | A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitropenmrs · openmrs · CWE-352 | Высокая8,0 | — | 0,3 % | 11 мар. 2025 г. |
31Наблюдать | CVE-2022-23612Эксплойта нет | Directory Traversal in OpenMRS Startup Filteropenmrs · openmrs · CWE-22 | Высокая7,5 | — | 1,9 % | 22 февр. 2022 г. |
27Наблюдать | CVE-2014-8073Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of adopenmrs · openmrs · CWE-352 | Средняя6,8 | — | 1,1 % | 23 окт. 2014 г. |
27Наблюдать | CVE-2025-25927Эксплойта нет | A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET requestopenmrs · openmrs · CWE-352 | Средняя6,8 | — | 0,3 % | 11 мар. 2025 г. |
24Наблюдать | CVE-2020-5732Эксплойта нет | In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticopenmrs · openmrs · CWE-601 | Средняя6,1 | — | 1,2 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2020-5733Эксплойта нет | In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentiopenmrs · openmrs · CWE-601 | Средняя6,1 | — | 1,2 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2020-5731Эксплойта нет | In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.openmrs · openmrs · CWE-79 | Средняя6,1 | — | 1,1 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2020-5730Эксплойта нет | In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.openmrs · openmrs · CWE-79 | Средняя6,1 | — | 1,1 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2020-5729Эксплойта нет | In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.openmrs · openmrs · CWE-79 | Средняя6,1 | — | 1,1 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2020-5728Эксплойта нет | OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).openmrs · openmrs · CWE-20 | Средняя6,1 | — | 1,1 % | 17 апр. 2020 г. |
24Наблюдать | CVE-2021-4289Эксплойта нет | OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scriptingopenmrs · reference application · CWE-79 | Средняя6,1 | — | 1,0 % | 27 дек. 2022 г. |
24Наблюдать | CVE-2021-4284Эксплойта нет | OpenMRS HTML Form Entry UI Framework Integration Module cross site scriptingopenmrs · htmlformentryui · CWE-79 | Средняя6,1 | — | 0,9 % | 27 дек. 2022 г. |
24Наблюдать | CVE-2020-36636Эксплойта нет | OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scriptingopenmrs · admin ui module · CWE-79 | Средняя6,1 | — | 0,9 % | 27 дек. 2022 г. |
24Наблюдать | CVE-2022-4727Эксплойта нет | OpenMRS Appointment Scheduling Module Notes AppointmentRequest.java getNotes cross site scriptingopenmrs · appointment scheduling module · CWE-707 | Средняя6,1 | — | 0,9 % | 27 дек. 2022 г. |
24Наблюдать | CVE-2021-4288Эксплойта нет | OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scriptingopenmrs · reference application · CWE-79 | Средняя6,1 | — | 0,9 % | 27 дек. 2022 г. |
24Наблюдать | CVE-2021-4291Эксплойта нет | OpenMRS Admin UI Module location.gsp cross site scriptingopenmrs · admin ui module · CWE-79 | Средняя6,1 | — | 0,9 % | 27 дек. 2022 г. |
- CVE-2018-1927669На этой неделе
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitra
КритическаяCVSS 9,8Готовый эксплойтEPSS 99 %openmrs · openmrs21 мар. 2019 г.
- CVE-2017-1279640В плане
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenti
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %openmrs · openmrs23 окт. 2017 г.
- CVE-2017-1279540В плане
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openmrs · openmrs-module-htmlformentry10 мая 2019 г.
- CVE-2018-1652140В плане
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openmrs · html form entry5 сент. 2018 г.
- CVE-2021-4309439Наблюдать
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openmrs · openmrs10 мая 2022 г.
- CVE-2026-4007637Наблюдать
OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %openmrs · openmrs6 мая 2026 г.
- CVE-2020-2462136Наблюдать
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %openmrs · htmlformentry25 сент. 2020 г.
- CVE-2017-799035Наблюдать
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openmrs · openmrs module reporting20 апр. 2017 г.
- CVE-2026-4007532Наблюдать
OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %openmrs · openmrs5 мая 2026 г.
- CVE-2025-2592832Наблюдать
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitr
ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %openmrs · openmrs11 мар. 2025 г.
- CVE-2022-2361231Наблюдать
Directory Traversal in OpenMRS Startup Filter
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openmrs · openmrs22 февр. 2022 г.
- CVE-2014-807327Наблюдать
Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of ad
СредняяCVSS 6,8Эксплойта нетEPSS 1 %openmrs · openmrs23 окт. 2014 г.
- CVE-2025-2592727Наблюдать
A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request
СредняяCVSS 6,8Эксплойта нетEPSS 0 %openmrs · openmrs11 мар. 2025 г.
- CVE-2020-573224Наблюдать
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentic
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2020-573324Наблюдать
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenti
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2020-573124Наблюдать
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2020-573024Наблюдать
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2020-572924Наблюдать
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2020-572824Наблюдать
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · openmrs17 апр. 2020 г.
- CVE-2021-428924Наблюдать
OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · reference application27 дек. 2022 г.
- CVE-2021-428424Наблюдать
OpenMRS HTML Form Entry UI Framework Integration Module cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · htmlformentryui27 дек. 2022 г.
- CVE-2020-3663624Наблюдать
OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · admin ui module27 дек. 2022 г.
- CVE-2022-472724Наблюдать
OpenMRS Appointment Scheduling Module Notes AppointmentRequest.java getNotes cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · appointment scheduling module27 дек. 2022 г.
- CVE-2021-428824Наблюдать
OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · reference application27 дек. 2022 г.
- CVE-2021-429124Наблюдать
OpenMRS Admin UI Module location.gsp cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openmrs · admin ui module27 дек. 2022 г.