Loading
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
Use CWE-352, Openmrs vendor hub and Openmrs Module Reporting product page to widen CVE-2017-7990 into its surrounding weakness, vendor, and product context.