CVE-2021-43094: SQL Injection
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43094?
CVE-2021-43094 is an SQL Injection vulnerability that exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0.
How severe is CVE-2021-43094?
CVE-2021-43094 has a severity rating of 9.8, which is considered critical.
What software versions are affected by CVE-2021-43094?
CVE-2021-43094 affects OpenMRS Reference Application Standalone Edition up to version 2.11 and Platform Standalone Edition up to version 2.4.0.
How can I exploit CVE-2021-43094?
I'm sorry, but I cannot provide information on exploiting vulnerabilities.
How can I fix CVE-2021-43094?
To fix CVE-2021-43094, it is recommended to update OpenMRS Reference Application Standalone Edition and Platform Standalone Edition to versions above 2.11 and 2.4.0 respectively.