Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r22g-hfmg-72m8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.

A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.

EPSS

Процентиль: 90%
0.05872
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.

EPSS

Процентиль: 90%
0.05872
Низкий