A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.
Metrics
Affected Vendors & Products
References
History
Wed, 21 May 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Openmrs
Openmrs openmrs |
|
CPEs | cpe:2.3:a:openmrs:openmrs:2.4.3:build0ff0ed:*:*:*:*:*:* | |
Vendors & Products |
Openmrs
Openmrs openmrs |
Wed, 12 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
Metrics |
cvssV3_1
|
Tue, 11 Mar 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-03-11T00:00:00.000Z
Updated: 2025-03-12T15:22:45.214Z
Reserved: 2025-02-07T00:00:00.000Z
Link: CVE-2025-25927

Updated: 2025-03-12T15:22:38.860Z

Status : Analyzed
Published: 2025-03-11T20:15:17.050
Modified: 2025-05-21T19:15:51.170
Link: CVE-2025-25927

No data.