Cross-Site Scripting Vulnerability in OpenMRS by OpenMRS Inc.
CVE-2020-5731
6.1MEDIUM
What is CVE-2020-5731?
The OpenMRS application, specifically versions 2.9 and earlier, has a vulnerability located in the app parameter for the ActiveVisit's page, which is susceptible to cross-site scripting attacks. This flaw allows malicious actors to inject arbitrary web scripts into the application, potentially leading to unauthorized data access and manipulation. Users and system administrators are advised to apply necessary security measures or upgrade to safer versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
OpenMRS Versions 2.90 and prior
