Loading
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page that is able to trigger a UI Framework Error is susceptible to this issue.
Use CWE-79, Openmrs vendor hub and Openmrs product page to widen CVE-2020-5729 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-43094, CVE-2025-25928 and CVE-2022-23612 for nearby disclosures in the same product family.