CVE-2020-5733: Openmrs

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information.

Affected products

  • Openmrs Openmrs: up to and including 2.9.0

Published 2020-04-17. Last modified 2026-06-17.