AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-12796

CRITICAL · CVSS 9.8 EPSS 4.24%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-23 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2017-12796
Severity
CRITICAL
CVSS
9.8
EPSS
4.24%

Original NVD Description

The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users are able to execute operating system commands by crafting malicious XML payloads, as demonstrated by a single admin/reports/reportSchemaXml.form request.

Related CVEs

Other vulnerabilities affecting the same vendor(s)