High severity8.8NVD Advisory· Published Apr 21, 2017· Updated May 13, 2026
CVE-2017-7990
CVE-2017-7990
Description
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
Affected products
1- cpe:2.3:a:openmrs:openmrs_module_reporting:1.12.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/openmrs/openmrs-module-reporting/pull/141/commits/0023a659288538d2763835847d3414ecb18b931anvdPatch
- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.