Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenMRS 路径遍历漏洞
Vulnerability Description
OpenMRS是美国OpenMRS公司的一套开源的电子病历系统。 OpenMRS 3.11.0之前版本存在安全漏洞。该漏洞源于htmlformentry模块中发现了一个远程代码执行(RCE)。攻击者可利用该漏洞通过利用路径遍历,可以将恶意的Velocity模板语言文件写入目录。然后可以访问和执行该文件。
CVSS Information
N/A
Vulnerability Type
N/A