{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2021-4284","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2022-12-27T09:50:35.466Z","datePublished":"2022-12-27T09:51:38.273Z","dateUpdated":"2024-08-03T17:23:10.305Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2022-12-27T09:51:38.273Z"},"title":"OpenMRS HTML Form Entry UI Framework Integration Module cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"OpenMRS","product":"HTML Form Entry UI Framework Integration Module","versions":[{"version":"1.x","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name of the patch is 811990972ea07649ae33c4b56c61c3b520895f07. It is recommended to upgrade the affected component. The identifier VDB-216873 was assigned to this vulnerability."},{"lang":"de","value":"Es wurde eine Schwachstelle in OpenMRS HTML Form Entry UI Framework Integration Module bis 1.x entdeckt. Sie wurde als problematisch eingestuft. Dabei betrifft es einen unbekannter Codeteil. Durch Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Ein Aktualisieren auf die Version 2.0.0 vermag dieses Problem zu lösen. Der Patch wird als 811990972ea07649ae33c4b56c61c3b520895f07 bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}}],"timeline":[{"time":"2022-12-27T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2022-12-27T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2022-12-27T10:56:35.000Z","lang":"en","value":"VulDB last update"}],"references":[{"url":"https://vuldb.com/?id.216873","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.216873","tags":["signature","permissions-required"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/pull/51","tags":["issue-tracking"]},{"url":"https://issues.openmrs.org/browse/RA-1424?filter=-1","tags":["related"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/commit/811990972ea07649ae33c4b56c61c3b520895f07","tags":["patch"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/releases/tag/2.0.0","tags":["patch"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T17:23:10.305Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.216873","tags":["vdb-entry","x_transferred"]},{"url":"https://vuldb.com/?ctiid.216873","tags":["signature","permissions-required","x_transferred"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/pull/51","tags":["issue-tracking","x_transferred"]},{"url":"https://issues.openmrs.org/browse/RA-1424?filter=-1","tags":["related","x_transferred"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/commit/811990972ea07649ae33c4b56c61c3b520895f07","tags":["patch","x_transferred"]},{"url":"https://github.com/openmrs/openmrs-module-htmlformentryui/releases/tag/2.0.0","tags":["patch","x_transferred"]}]}]}}