OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.919
EPSS Ranking 99.7%