CVE Database
/

CVE-2020-5732

Back to search

CVE-2020-5732

Published: Apr 17, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.

VendorProductVersions

n/a

OpenMRS

affected
Versions 2.90 and prior

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now