OpenMRS kayıtları
openmrs üreticisine ait 31 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3,2
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %29
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data2
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
31 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2018-19276Silahlaştırılmış | OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitraopenmrs · openmrs · CWE-502 | Kritik9,8 | — | %98,7 | 21 Mar 2019 |
40Planlayın | CVE-2017-12796İstismar yok | The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authentiopenmrs · openmrs · CWE-502 | Kritik9,8 | — | %4,2 | 23 Eki 2017 |
40Planlayın | CVE-2017-12795İstismar yok | OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).openmrs · openmrs-module-htmlformentry · CWE-20 | Kritik9,8 | — | %2,3 | 10 May 2019 |
40Planlayın | CVE-2018-16521İstismar yok | An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.openmrs · html form entry · CWE-611 | Kritik9,8 | — | %1,9 | 5 Eyl 2018 |
39İzleyin | CVE-2021-43094İstismar yok | An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 viaopenmrs · openmrs · CWE-89 | Kritik9,8 | — | %1,3 | 10 May 2022 |
37İzleyin | CVE-2026-40076İstismar yok | OpenMRS Core arbitrary file write and code execution via Zip Slip in module uploadopenmrs · openmrs · CWE-22 | Kritik9,4 | — | %0,9 | 6 May 2026 |
36İzleyin | CVE-2020-24621İstismar yok | A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.openmrs · htmlformentry · CWE-22 | Yüksek8,8 | — | %3,2 | 25 Eyl 2020 |
35İzleyin | CVE-2017-7990İstismar yok | The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insertopenmrs · openmrs module reporting · CWE-352 | Yüksek8,8 | — | %1,1 | 20 Nis 2017 |
32İzleyin | CVE-2026-40075İstismar yok | OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServletopenmrs · openmrs · CWE-22 | Yüksek8,2 | — | %0,7 | 5 May 2026 |
32İzleyin | CVE-2025-25928İstismar yok | A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitropenmrs · openmrs · CWE-352 | Yüksek8,0 | — | %0,3 | 11 Mar 2025 |
31İzleyin | CVE-2022-23612İstismar yok | Directory Traversal in OpenMRS Startup Filteropenmrs · openmrs · CWE-22 | Yüksek7,5 | — | %1,9 | 22 Şub 2022 |
27İzleyin | CVE-2014-8073İstismar yok | Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of adopenmrs · openmrs · CWE-352 | Orta6,8 | — | %1,1 | 23 Eki 2014 |
27İzleyin | CVE-2025-25927İstismar yok | A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET requestopenmrs · openmrs · CWE-352 | Orta6,8 | — | %0,3 | 11 Mar 2025 |
24İzleyin | CVE-2020-5732İstismar yok | In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticopenmrs · openmrs · CWE-601 | Orta6,1 | — | %1,2 | 17 Nis 2020 |
24İzleyin | CVE-2020-5733İstismar yok | In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentiopenmrs · openmrs · CWE-601 | Orta6,1 | — | %1,2 | 17 Nis 2020 |
24İzleyin | CVE-2020-5731İstismar yok | In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.openmrs · openmrs · CWE-79 | Orta6,1 | — | %1,1 | 17 Nis 2020 |
24İzleyin | CVE-2020-5730İstismar yok | In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.openmrs · openmrs · CWE-79 | Orta6,1 | — | %1,1 | 17 Nis 2020 |
24İzleyin | CVE-2020-5729İstismar yok | In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.openmrs · openmrs · CWE-79 | Orta6,1 | — | %1,1 | 17 Nis 2020 |
24İzleyin | CVE-2020-5728İstismar yok | OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).openmrs · openmrs · CWE-20 | Orta6,1 | — | %1,1 | 17 Nis 2020 |
24İzleyin | CVE-2021-4289İstismar yok | OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scriptingopenmrs · reference application · CWE-79 | Orta6,1 | — | %1,0 | 27 Ara 2022 |
24İzleyin | CVE-2021-4284İstismar yok | OpenMRS HTML Form Entry UI Framework Integration Module cross site scriptingopenmrs · htmlformentryui · CWE-79 | Orta6,1 | — | %1,0 | 27 Ara 2022 |
24İzleyin | CVE-2020-36636İstismar yok | OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scriptingopenmrs · admin ui module · CWE-79 | Orta6,1 | — | %1,0 | 27 Ara 2022 |
24İzleyin | CVE-2021-4288İstismar yok | OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scriptingopenmrs · reference application · CWE-79 | Orta6,1 | — | %0,9 | 27 Ara 2022 |
24İzleyin | CVE-2021-4292İstismar yok | OpenMRS Admin UI Module Manage Privilege Page privilege.gsp cross site scriptingopenmrs · admin ui module · CWE-79 | Orta6,1 | — | %0,9 | 27 Ara 2022 |
24İzleyin | CVE-2021-4291İstismar yok | OpenMRS Admin UI Module location.gsp cross site scriptingopenmrs · admin ui module · CWE-79 | Orta6,1 | — | %0,9 | 27 Ara 2022 |
- CVE-2018-1927669Bu hafta
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitra
KritikCVSS 9,8SilahlaştırılmışEPSS %99openmrs · openmrs21 Mar 2019
- CVE-2017-1279640Planlayın
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenti
KritikCVSS 9,8İstismar yokEPSS %4openmrs · openmrs23 Eki 2017
- CVE-2017-1279540Planlayın
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
KritikCVSS 9,8İstismar yokEPSS %2openmrs · openmrs-module-htmlformentry10 May 2019
- CVE-2018-1652140Planlayın
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
KritikCVSS 9,8İstismar yokEPSS %2openmrs · html form entry5 Eyl 2018
- CVE-2021-4309439İzleyin
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via
KritikCVSS 9,8İstismar yokEPSS %1openmrs · openmrs10 May 2022
- CVE-2026-4007637İzleyin
OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload
KritikCVSS 9,4İstismar yokEPSS %1openmrs · openmrs6 May 2026
- CVE-2020-2462136İzleyin
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.
YüksekCVSS 8,8İstismar yokEPSS %3openmrs · htmlformentry25 Eyl 2020
- CVE-2017-799035İzleyin
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert
YüksekCVSS 8,8İstismar yokEPSS %1openmrs · openmrs module reporting20 Nis 2017
- CVE-2026-4007532İzleyin
OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet
YüksekCVSS 8,2İstismar yokEPSS %1openmrs · openmrs5 May 2026
- CVE-2025-2592832İzleyin
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitr
YüksekCVSS 8,0İstismar yokEPSS %0openmrs · openmrs11 Mar 2025
- CVE-2022-2361231İzleyin
Directory Traversal in OpenMRS Startup Filter
YüksekCVSS 7,5İstismar yokEPSS %2openmrs · openmrs22 Şub 2022
- CVE-2014-807327İzleyin
Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of ad
OrtaCVSS 6,8İstismar yokEPSS %1openmrs · openmrs23 Eki 2014
- CVE-2025-2592727İzleyin
A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request
OrtaCVSS 6,8İstismar yokEPSS %0openmrs · openmrs11 Mar 2025
- CVE-2020-573224İzleyin
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentic
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2020-573324İzleyin
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenti
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2020-573124İzleyin
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2020-573024İzleyin
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2020-572924İzleyin
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2020-572824İzleyin
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · openmrs17 Nis 2020
- CVE-2021-428924İzleyin
OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · reference application27 Ara 2022
- CVE-2021-428424İzleyin
OpenMRS HTML Form Entry UI Framework Integration Module cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · htmlformentryui27 Ara 2022
- CVE-2020-3663624İzleyin
OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · admin ui module27 Ara 2022
- CVE-2021-428824İzleyin
OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · reference application27 Ara 2022
- CVE-2021-429224İzleyin
OpenMRS Admin UI Module Manage Privilege Page privilege.gsp cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · admin ui module27 Ara 2022
- CVE-2021-429124İzleyin
OpenMRS Admin UI Module location.gsp cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1openmrs · admin ui module27 Ara 2022