The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2017-04-21T00:00:00Z

Updated: 2024-09-16T22:25:18.957Z

Reserved: 2017-04-20T00:00:00Z

Link: CVE-2017-7990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-04-21T00:59:00.180

Modified: 2017-04-26T16:51:05.540

Link: CVE-2017-7990

cve-icon Redhat

No data.