CVE-2017-7990: XSS
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7990?
CVE-2017-7990 is classified as a medium severity vulnerability due to its potential for CSRF and XSS attacks.
How do I fix CVE-2017-7990?
To mitigate CVE-2017-7990, upgrade to a patched version of the OpenMRS Reporting Module that addresses the vulnerability.
What type of vulnerability is CVE-2017-7990?
CVE-2017-7990 is a Cross-Site Request Forgery (CSRF) vulnerability that can lead to Cross-Site Scripting (XSS) attacks.
Who is affected by CVE-2017-7990?
Users of OpenMRS Reporting Module version 1.12.0 are affected by CVE-2017-7990.
Can CVE-2017-7990 lead to data loss?
While CVE-2017-7990 primarily enables JavaScript injection, it may lead to administrative hijacking, which could compromise sensitive data.