PT-2020-14040 · Openclinic · Openclinic Ga

Published

2020-07-29

·

Updated

2020-07-30

·

CVE-2020-14492

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClinic GA versions 5.09.02 through 5.89.05b
Description The issue arises from the improper neutralization of user-controllable input, potentially allowing the execution of malicious code within the user's browser.
Recommendations For OpenClinic GA versions 5.09.02 through 5.89.05b, consider implementing proper input validation and sanitization to prevent malicious code execution. As a temporary workaround, restrict user input to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14492

Affected Products

Openclinic Ga