PT-2026-57522 · Bahmni · Bahmnicore
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Bahmni bahmnicore versions prior to 0.93.1
Description
An issue exists in the Search Endpoint component where the
additionalParams function within the '/openmrs/ws/rest/v1/bahmnicore/sql' endpoint is susceptible to SQL injection. This occurs when the test argument is manipulated, allowing a remote attacker to execute unauthorized SQL commands.Recommendations
Upgrade to version 0.93.1, 1.0.1, 1.1.1, 1.2.1, 1.3.1, or 2.0.1.
As a temporary mitigation, restrict access to the '/openmrs/ws/rest/v1/bahmnicore/sql' endpoint or avoid using the
test argument.Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bahmnicore