OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which allows for the possibility of cross-site scripting.
References
Link Resource
https://www.tenable.com/security/research/tra-2020-18 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: tenable

Published: 2020-04-17T18:29:48

Updated: 2020-04-17T18:29:48

Reserved: 2020-01-06T00:00:00


Link: CVE-2020-5728

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-17T19:15:14.793

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-5728

JSON object: View

cve-icon Redhat Information

No data.