Vulnerability Description
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openmrs | Openmrs Module Reporting | 1.12.0 |
Related Weaknesses (CWE)
References
- https://github.com/openmrs/openmrs-module-reporting/pull/141/commits/0023a659288Patch
- https://www.youtube.com/watch?v=pfrIaNvIuFYExploitThird Party Advisory
- https://github.com/openmrs/openmrs-module-reporting/pull/141/commits/0023a659288Patch
- https://www.youtube.com/watch?v=pfrIaNvIuFYExploitThird Party Advisory
FAQ
What is CVE-2017-7990?
CVE-2017-7990 is a vulnerability with a CVSS score of 8.8 (HIGH). The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReport...
How severe is CVE-2017-7990?
CVE-2017-7990 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7990?
Check the references section above for vendor advisories and patch information. Affected products include: Openmrs Openmrs Module Reporting.