Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv2x-9h7w-52q7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which allows for the possibility of cross-site scripting.

OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which allows for the possibility of cross-site scripting.

EPSS

Процентиль: 55%
0.00328
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is insufficient validation for this parameter, which allows for the possibility of cross-site scripting.

EPSS

Процентиль: 55%
0.00328
Низкий

Дефекты

CWE-20