CVE-2025-25927: CSRF
Published Mar 11, 2025
·Updated
A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.
Affected Software
2 affected components
OpenMRS Openmrs
OpenMRS Openmrs=2.4.3-build0ff0ed
Event History
Mar 11, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25927?
CVE-2025-25927 has been classified as a medium severity vulnerability due to its potential for CSRF attacks.
2
How do I fix CVE-2025-25927?
To fix CVE-2025-25927, it is recommended to update OpenMRS to the latest version that addresses this CSRF vulnerability.
3
What type of attacks can be executed with CVE-2025-25927?
CVE-2025-25927 allows attackers to execute arbitrary operations on OpenMRS installations through crafted GET requests, which can lead to unauthorized actions.
4
Which versions of OpenMRS are affected by CVE-2025-25927?
CVE-2025-25927 affects OpenMRS version 2.4.3 Build 0ff0ed.
5
Is CVE-2025-25927 exploitable remotely?
Yes, CVE-2025-25927 is exploitable remotely since it relies on CSRF, which does not require direct access to the server.