Vulnerabilities (CVE)

Filtered by vendor Openmrs Subscribe
Filtered by product Htmlformentry
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-24621 1 Openmrs 1 Htmlformentry 2024-02-04 6.5 MEDIUM 8.8 HIGH
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.