PT-2020-14034 · Openclinic · Openclinic Ga
Published
2020-07-29
·
Updated
2020-07-29
·
CVE-2020-14486
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClinic GA versions 5.09.02 through 5.89.05b
Description
The issue allows an attacker to bypass permission and authorization checks by ignoring the redirect of a permission failure, potentially enabling unauthorized execution of commands.
Recommendations
For OpenClinic GA versions 5.09.02 through 5.89.05b, consider implementing additional authorization checks to prevent bypassing of permission checks as a temporary workaround until a patch is available.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclinic Ga