The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.
{ "versions": [ { "introduced": "0" }, { "last_affected": "1.12.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7990.json"