CVE-2020-5732: Medium severity OpenMRS Openmrs vulnerability
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5732?
CVE-2020-5732 is considered a moderate severity vulnerability due to its potential for unauthorized access to restricted features.
How do I fix CVE-2020-5732?
To fix CVE-2020-5732, upgrade to OpenMRS version 2.9.1 or later, where this vulnerability is addressed.
What impact does CVE-2020-5732 have on OpenMRS?
CVE-2020-5732 allows unauthenticated users to exploit the import functionality of the Data Exchange Module, typically reserved for administrators.
Who is affected by CVE-2020-5732?
CVE-2020-5732 affects users of OpenMRS version 2.9 and prior implementations.
Is CVE-2020-5732 an application vulnerability?
Yes, CVE-2020-5732 is an application-level vulnerability within OpenMRS that mismanages user authentication for a specific module.