The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
{
"extracted_events": [
{
"introduced": "1.12.0"
},
{
"last_affected": "1.12.0"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:openmrs:openmrs_module_reporting:1.12.0:*:*:*:*:*:*:*"
}