CVE-2020-5729: XSS
Published Apr 17, 2020
·Updated
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is susceptible to this issue.
Affected Software
1 affected component
OpenMRS Openmrs<=2.9.0
Event History
Apr 17, 2020
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5729?
CVE-2020-5729 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2020-5729?
To fix CVE-2020-5729, upgrade OpenMRS to version 2.9.1 or later.
3
What type of vulnerability is CVE-2020-5729?
CVE-2020-5729 is an XSS (Cross-Site Scripting) vulnerability.
4
Which versions of OpenMRS are affected by CVE-2020-5729?
OpenMRS versions 2.9.0 and earlier are affected by CVE-2020-5729.
5
What can exploited CVE-2020-5729 allow an attacker to do?
Exploiting CVE-2020-5729 can allow an attacker to inject arbitrary scripts into user browsers.