CVE-2025-25929
11.03.2025, 20:15
A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.
Awaiting analysis
This vulnerability is currently awaiting analysis.