Open redirect in OpenMRS - #VU129553
Published: January 30, 2025 / Updated: May 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to open redirect in redirect handling when processing user-controlled URLs. A remote attacker can supply a crafted link or redirect target to redirect users to an untrusted site.
The advisory describes this issue as a phishing vulnerability.