EIP-2026-119682
PRE-CVEOpenMRS 2.3 (1.11.4) - XML External Entity Processing
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119682. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) vulnerability in OpenMRS 2.3 (Platform 1.11.4) by crafting a malicious XML file within a ZIP archive. It allows an authenticated attacker to read local files (e.g., /etc/passwd) by exploiting improper XML entity parsing in the Metadata Sharing module.
Description
OpenMRS 2.3 (1.11.4) - XML External Entity Processing
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) vulnerability in OpenMRS 2.3 (Platform 1.11.4) by crafting a malicious XML file within a ZIP archive. It allows an authenticated attacker to read local files (e.g., /etc/passwd) by exploiting improper XML entity parsing in the Metadata Sharing module.