CVE-2020-5730: XSS
Published Apr 17, 2020
·Updated
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
Affected Software
1 affected component
OpenMRS Openmrs<=2.9.0
Event History
Apr 17, 2020
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5730?
CVE-2020-5730 has been classified as a medium severity vulnerability due to its cross-site scripting risk.
2
How do I fix CVE-2020-5730?
To fix CVE-2020-5730, users should upgrade to OpenMRS version 2.10 or later, where the vulnerability has been addressed.
3
What is the impact of CVE-2020-5730?
The impact of CVE-2020-5730 allows an attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to data theft.
4
Does CVE-2020-5730 affect all users of OpenMRS?
CVE-2020-5730 affects all users of OpenMRS versions 2.9 and prior, specifically those using the login page.
5
Is CVE-2020-5730 a serious threat to OpenMRS users?
Yes, CVE-2020-5730 represents a serious threat as it can be exploited to carry out cross-site scripting attacks against users.