Remote Code Execution Vulnerability in OpenMRS HTML Form Entry Module
CVE-2020-24621
8.8HIGH
What is CVE-2020-24621?
A remote code execution vulnerability exists in the HTML Form Entry module for OpenMRS, prior to version 3.11.0. This vulnerability allows an attacker to exploit a path traversal issue, enabling the creation of a malicious Velocity Template Language (VTL) file in a designated directory. Once the file is created, it can be accessed and executed, potentially compromising the system's security. Mitigating this risk is crucial for users of the affected versions.
