Vulnerabilities > Openmrs > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2018-19276 Deserialization of Untrusted Data vulnerability in Openmrs
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
network
low complexity
openmrs CWE-502
critical
9.8
2017-10-23 CVE-2017-12796 Deserialization of Untrusted Data vulnerability in Openmrs
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects.
network
low complexity
openmrs CWE-502
critical
10.0