VYPR
Critical severity9.8OSV Advisory· Published Mar 21, 2019· Updated Jun 17, 2026

CVE-2018-19276

CVE-2018-19276

Description

OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: 1.12.0, 2.0.0, 2.0.1, …
  • Openmrs/Openmrs2 versions
    cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:*range: >=1.12.0,<1.12.1
    • (no CPE)range: <2.24.0

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.