OpenMRS是美国OpenMRS公司的一套开源的电子病历系统。 OpenMRS openmrs-module-htmlformentryui 2.0.0之前版本存在跨站脚本漏洞,该漏洞源于单输入 UI 框架集成模块中存在未知部分, 操纵导致跨站脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenMRS | HTML Form Entry UI Framework Integration Module | 1.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-36635 | 3.5 LOW | OpenMRS Appointment Scheduling Module AppointmentTypeValidator.java validateFieldName cros |
| CVE-2020-36636 | 3.5 LOW | OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross si |
| CVE-2021-4288 | 3.5 LOW | OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scripting |
| CVE-2021-4289 | 3.5 LOW | OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post |
| CVE-2021-4291 | 3.5 LOW | OpenMRS Admin UI Module location.gsp cross site scripting |
| CVE-2021-4292 | 3.5 LOW | OpenMRS Admin UI Module Manage Privilege Page privilege.gsp cross site scripting |
No comments yet