PT-2020-14039 · Openclinic · Openclinic Ga

Published

2020-07-20

·

Updated

2020-07-22

·

CVE-2020-14491

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClinic GA versions 5.09.02 through 5.89.05b
Description The issue arises from improper permission checks before executing SQL queries, potentially allowing a low-privilege user to access privileged information.
Recommendations For OpenClinic GA versions 5.09.02 through 5.89.05b, consider restricting access to SQL query execution until a proper fix is applied, ensuring that only authorized users can perform such actions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14491

Affected Products

Openclinic Ga