CVE-2020-5732

Publication date

2020-04-17 18:27:00

Family

tenable

State

PUBLISHED

Description

In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.