CVE-2018-19276 is a critical Insecure Object Deserialization vulnerability affecting OpenMRS versions prior to 2.24.0. This flaw allows unauthenticated attackers to execute arbitrary commands on the targeted system by sending crafted XML data in a request body. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. Exploit modules are publicly available, including a Metasploit module and Nuclei templates, and it has garnered substantial community discussion, suggesting a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.12.0, < 1.12.1CPE matchmatch criteria | cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:* | ||
>= 2.0.0, < 2.0.8CPE matchmatch criteria | cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.4CPE matchmatch criteria | cpe:2.3:a:openmrs:openmrs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.