PT-2020-14033 · Openclinic · Openclinic Ga
Published
2020-07-20
·
Updated
2020-07-22
·
CVE-2020-14485
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClinic GA versions 5.09.02 through 5.89.05b
Description
The issue may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality. This could potentially allow execution of admin functions, such as SQL queries.
Recommendations
For OpenClinic GA versions 5.09.02 through 5.89.05b, consider restricting access to admin functions and limiting the execution of SQL queries until a fix is available. As a temporary workaround, restrict the use of crafted requests to initiate sessions with limited functionality. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclinic Ga