Data Exposure Vulnerability in OpenMRS by OpenMRS
CVE-2020-5733
6.1MEDIUM
What is CVE-2020-5733?
In OpenMRS versions 2.9 and earlier, the Data Exchange Module's export functionality is susceptible to an improper access control issue. When an unauthenticated user tries to access the export features, the system fails to redirect them to a login page. This oversight can allow unauthorized individuals to potentially export sensitive data, posing a risk for data breaches and unauthorized information access.
Affected Version(s)
OpenMRS Versions 2.90 and prior
