The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
References
Link | Resource |
---|---|
https://github.com/openmrs/openmrs-module-reporting/pull/141/commits/0023a659288538d2763835847d3414ecb18b931a#diff-50e25eddc5909110fa3d31090877c2fd | Patch |
https://www.youtube.com/watch?v=pfrIaNvIuFY | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:00
Updated: 2022-10-03T16:23:00
Reserved: 2022-10-03T00:00:00
Link: CVE-2017-7990
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-04-21T00:59:00.180
Modified: 2017-04-26T16:51:05.540
Link: CVE-2017-7990
JSON object: View
Redhat Information
No data.
CWE