CyberRota Analysis
AI-GeneratedAuthenticated users in OpenMRS versions prior to 1.23.0 and 2.10.0 can exploit unrestricted access to the `startHl7ArchiveMigration` method, which is intended for admin-level accounts, potentially allowing unauthorized administrative actions. This vulnerability poses a significant risk to the integrity and confidentiality of medical records managed by the platform. Organizations using affected versions should prioritize upgrading to the patched releases to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level accounts. Versions 1.23.0 and 2.10.0 patch the issue.