Un XML External Entity (XXE) vulnerabilità esiste in HTML modulo di iscrizione 3.7.0, come distribuito in OpenMRS Riferimento Application 2.8.0. |
https://github.com/openmrs/openmrs-module-htmlformentry/pull/137 https://github.com/openmrs/openmrs-module-htmlformentry/pull/138 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16521 |
Vulnerabilità: CVE-2018-16521
