Open redirect in OpenMRS - #VU129553
Published: January 30, 2025 / Updated: May 4, 2026
OpenMRS
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to open redirect in redirect handling when processing user-controlled URLs. A remote attacker can supply a crafted link or redirect target to redirect users to an untrusted site.
The advisory describes this issue as a phishing vulnerability.