Back to overview

CVE-2018-19276

CRITICAL
10.0
CVSS 3.0
Description
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

Metadata

CVE ID
CVE-2018-19276
State
PUBLISHED
Assigner
mitre
Reserved
2018-11-14 00:00 UTC
Published
2019-03-17 21:30 UTC
Last updated
2024-08-05 11:30 UTC
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.0
CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.0 cna CVSS:3.0/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Back to overview