A remote code execution (RCE) vulnerability was discovered in the...
Vulnerability Description
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-24621
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/openmrs/openmrs-module-htmlformentry/pull/178
- https://issues.openmrs.org/browse/HTML-730
- https://github.com/openmrs/openmrs-module-uiframework/pull/59
- https://www.contrastsecurity.com/security-influencers
- https://www.contrastsecurity.com/security-influencers/authenticated-remote-code-execution-openmrs
More from openmrs
View All →Affected Vendor
openmrs
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.