CVE-2018-16521: XEE
Published Sep 5, 2018
·Updated
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
Affected Software
2 affected components
OpenMRS HTML Form Entry=3.7.0
OpenMRS Reference Application=2.8.0
Remediation
Event History
Sep 5, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16521?
CVE-2018-16521 has a high severity rating due to its potential to lead to sensitive data exposure through an XML External Entity vulnerability.
2
How do I fix CVE-2018-16521?
To fix CVE-2018-16521, upgrade to the latest version of HTML Form Entry or apply relevant patches provided by OpenMRS.
3
What causes CVE-2018-16521?
CVE-2018-16521 is caused by improper validation of XML input leading to the processing of external entities.
4
Which versions are affected by CVE-2018-16521?
CVE-2018-16521 affects HTML Form Entry version 3.7.0 and OpenMRS Reference Application version 2.8.0.
5
What are the potential impacts of CVE-2018-16521?
The potential impacts of CVE-2018-16521 include unauthorized access to sensitive data and potential server-side request forgery.