CVE-2020-24621: Path Traversal
Published Sep 25, 2020
·Updated
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
Affected Software
1 affected component
OpenMRS Htmlformentry Openmrs<3.11.0
Remediation
Event History
Sep 25, 2020
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24621?
CVE-2020-24621 is classified as a critical remote code execution (RCE) vulnerability.
2
How do I fix CVE-2020-24621?
To fix CVE-2020-24621, upgrade the htmlformentry module to version 3.11.0 or higher.
3
What does exploitation of CVE-2020-24621 allow an attacker to do?
Exploitation of CVE-2020-24621 allows an attacker to execute arbitrary code on the affected system.
4
What versions of htmlformentry are affected by CVE-2020-24621?
All versions of htmlformentry prior to 3.11.0 are affected by CVE-2020-24621.
5
Is CVE-2020-24621 a local or remote vulnerability?
CVE-2020-24621 is a remote vulnerability that can be exploited over the network.