Cross-Site Request Forgery Vulnerability in OpenMRS Software by OpenMRS Foundation
CVE-2025-25928
8HIGH
What is CVE-2025-25928?
A Cross-Site Request Forgery (CSRF) vulnerability exists in the /admin/users/user.form component of OpenMRS. This allows attackers to execute unauthorized actions by sending specially crafted GET requests. Successful exploitation may lead to unintended operations on behalf of authenticated users, potentially compromising sensitive data and user accounts. It's crucial for users of OpenMRS 2.4.3 Build 0ff0ed to apply the necessary security measures to mitigate this risk.
