OpenMRS Multiple Security Vulnerabilities
BID:70664
Info
OpenMRS Multiple Security Vulnerabilities
| Bugtraq ID: | 70664 |
| Class: | Unknown |
| CVE: |
CVE-2014-8071 CVE-2014-8072 CVE-2014-8073 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2014 12:00AM |
| Updated: | Oct 21 2014 12:00AM |
| Credit: | Mahendra |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenMRS Multiple Security Vulnerabilities
OpenMRS is prone to the following vulnerabilities:
1. Multiple HTML-injection vulnerabilities.
2. Multiple cross-site scripting vulnerabilities.
3. A cross-site request-forgery vulnerability.
4. An access-bypass vulnerability.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions, obtain sensitive information, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and perform actions in the vulnerable application in the context of the victim.
OpenMRS 2.1 is vulnerable; other versions may also be affected.
OpenMRS is prone to the following vulnerabilities:
1. Multiple HTML-injection vulnerabilities.
2. Multiple cross-site scripting vulnerabilities.
3. A cross-site request-forgery vulnerability.
4. An access-bypass vulnerability.
Successfully exploiting these issues may allow an attacker to bypass certain security restrictions, obtain sensitive information, execute arbitrary script code in the browser of an unsuspecting user, steal cookie-based authentication credentials, and perform actions in the vulnerable application in the context of the victim.
OpenMRS 2.1 is vulnerable; other versions may also be affected.
Exploit / POC
OpenMRS Multiple Security Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
OpenMRS Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].