CVE-2017-7990: Openmrs Module Reporting

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.

Affected products

  • Openmrs Openmrs Module Reporting: version 1.12.0 only

Published 2017-04-21. Last modified 2026-06-17.