PT-2020-17063 · Openclinic · Openclinic

Gerben Kleijn

·

Published

2020-12-03

·

Updated

2021-07-21

·

CVE-2020-28937

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClinic version 0.8.2
Description The issue allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application. This can be done via a direct request for the "/tests/" URI.
Recommendations For OpenClinic version 0.8.2, consider restricting access to the "/tests/" URI until a patch is available. As a temporary workaround, implement proper authentication mechanisms to prevent unauthenticated access to patient medical test results.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28937

Affected Products

Openclinic