CVE-2014-8073: CSRF
Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of administrators for requests that add a new user via a Save User action to admin/users/user.form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8073?
CVE-2014-8073 is considered a medium severity Cross-site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2014-8073?
To fix CVE-2014-8073, upgrade OpenMRS to a version that includes the relevant security patches addressing CSRF vulnerabilities.
What types of attacks can be executed through CVE-2014-8073?
CVE-2014-8073 allows remote attackers to perform unauthorized actions as an authenticated administrator, potentially leading to account hijacking.
Which versions of OpenMRS are affected by CVE-2014-8073?
CVE-2014-8073 specifically affects OpenMRS 2.1 Standalone Edition.
Is user authentication impacted by CVE-2014-8073?
Yes, CVE-2014-8073 compromises the authentication of administrators, enabling attackers to hijack their sessions.