CVE detail
CVE-2020-24621 — CVE-2020-24621
Published 2020-09-25 · Modified 2026-06-17 · Vendor openmrs · Product htmlformentry · Source nvd
HIGH
severity
CVSS-derived band
0.0315
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References