Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:openmrs:htmlformentry:1.9.0:*:*:*:*:openmrs:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2020-24621 |
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed. Published: September 25, 2020; 12:23:04 AM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0: 6.5 MEDIUM |