Back
CVE-2018-19276
CRITICAL
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
Published: Mar 21, 2019
Modified: Jun 17, 2026
CWE-502
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| openmrs | openmrs | * ≥ 1.12.0 < 1.12.1 |
| openmrs | openmrs | * ≥ 2.0.0 < 2.0.8 |
| openmrs | openmrs | * ≥ 2.1.0 < 2.1.4 |
GitHub Security Advisory GHSA-785q-xwp9-2xw7
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows...
References (10)
- http://packetstormsecurity.com/files/151553/OpenMRS-Platform-Insecure-Object-Deserialization.html Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155691/OpenMRS-Java-Deserialization-Remote-Code-Execution.html Third Party Advisory, VDB Entry
- https://know.bishopfox.com/advisories/news/2019/02/openmrs-insecure-object-deserialization Third Party Advisory
- https://talk.openmrs.org/t/critical-security-advisory-cve-2018-19276-2019-02-04/21607 Vendor Advisory
- https://www.exploit-db.com/exploits/46327/ Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/151553/OpenMRS-Platform-Insecure-Object-Deserialization.html Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155691/OpenMRS-Java-Deserialization-Remote-Code-Execution.html Third Party Advisory, VDB Entry
- https://know.bishopfox.com/advisories/news/2019/02/openmrs-insecure-object-deserialization Third Party Advisory
- https://talk.openmrs.org/t/critical-security-advisory-cve-2018-19276-2019-02-04/21607 Vendor Advisory
- https://www.exploit-db.com/exploits/46327/ Exploit, Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
98.71%
Top 0% most likely to be exploited
Threat Score
78.8 / 100
Data Sources
NVD
EPSS
GitHub