Beveiligingsadvies

CVE-2017-7990

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2017-04-21 00:00:00
Laatst bijgewerkt 2024-09-16 22:25:18
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.