High severity8.8NVD Advisory· Published Sep 25, 2020· Updated Jun 17, 2026
CVE-2020-24621
CVE-2020-24621
Description
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:openmrs:htmlformentry:*:*:*:*:*:openmrs:*:*+ 1 more
- cpe:2.3:a:openmrs:htmlformentry:*:*:*:*:*:openmrs:*:*range: <3.11.0
- (no CPE)range: <3.11.0
- OpenMRS/htmlformentrydescription
Patches
Vulnerability mechanics
References
5- github.com/openmrs/openmrs-module-htmlformentry/pull/178nvdPatchThird Party Advisory
- github.com/openmrs/openmrs-module-uiframework/pull/59nvdPatchThird Party Advisory
- www.contrastsecurity.com/security-influencers/authenticated-remote-code-execution-openmrsnvdExploitThird Party Advisory
- issues.openmrs.org/browse/HTML-730nvdVendor Advisory
- www.contrastsecurity.com/security-influencersnvdThird Party Advisory
News mentions
0No linked articles in our index yet.