CVE-2018-19276
21.03.2019, 16:00
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.Enginsight
Vendor | Product | Version |
---|---|---|
openmrs | openmrs | 1.12.0 ≤ 𝑥 < 1.12.1 |
openmrs | openmrs | 2.0.0 ≤ 𝑥 < 2.0.8 |
openmrs | openmrs | 2.1.0 ≤ 𝑥 < 2.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References