Vulnerabilities > Openmrs > Openmrs > 1.9.5

DATE CVE VULNERABILITY TITLE RISK
2022-05-10 CVE-2021-43094 SQL Injection vulnerability in Openmrs
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.
network
low complexity
openmrs CWE-89
critical
9.8
2022-02-22 CVE-2022-23612 Unspecified vulnerability in Openmrs
OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system.
network
low complexity
openmrs
7.5
2020-04-17 CVE-2020-5733 Open Redirect vulnerability in Openmrs
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it.
network
low complexity
openmrs CWE-601
6.1
2020-04-17 CVE-2020-5732 Open Redirect vulnerability in Openmrs
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it.
network
low complexity
openmrs CWE-601
6.1
2020-04-17 CVE-2020-5731 Cross-site Scripting vulnerability in Openmrs
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
network
low complexity
openmrs CWE-79
6.1
2020-04-17 CVE-2020-5730 Cross-site Scripting vulnerability in Openmrs
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
network
low complexity
openmrs CWE-79
6.1
2020-04-17 CVE-2020-5729 Cross-site Scripting vulnerability in Openmrs
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.
network
low complexity
openmrs CWE-79
6.1
2020-04-17 CVE-2020-5728 Improper Input Validation vulnerability in Openmrs
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).
network
low complexity
openmrs CWE-20
6.1
2017-10-23 CVE-2017-12796 Deserialization of Untrusted Data vulnerability in Openmrs
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects.
network
low complexity
openmrs CWE-502
critical
9.8