CVE-2020-5731: XSS
Published Apr 17, 2020
·Updated
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
Affected Software
1 affected component
OpenMRS Openmrs<=2.9.0
Event History
Apr 17, 2020
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-5731?
CVE-2020-5731 has a medium severity rating due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2020-5731?
To fix CVE-2020-5731, upgrade OpenMRS to version 2.10 or newer where the vulnerability has been addressed.
3
What types of attacks can CVE-2020-5731 lead to?
CVE-2020-5731 can lead to cross-site scripting attacks that could compromise user data and session integrity.
4
Which versions of OpenMRS are affected by CVE-2020-5731?
OpenMRS versions 2.9.0 and earlier are affected by CVE-2020-5731.
5
Is there a workaround for CVE-2020-5731?
There are no known effective workarounds for CVE-2020-5731; updating to a patched version is recommended for mitigation.