PT-2020-14033 · Openclinic · Openclinic Ga

Published

2020-07-20

·

Updated

2020-07-22

·

CVE-2020-14485

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClinic GA versions 5.09.02 through 5.89.05b
Description The issue may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality. This could potentially allow execution of admin functions, such as SQL queries.
Recommendations For OpenClinic GA versions 5.09.02 through 5.89.05b, consider restricting access to admin functions and limiting the execution of SQL queries until a fix is available. As a temporary workaround, restrict the use of crafted requests to initiate sessions with limited functionality. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14485

Affected Products

Openclinic Ga