PT-2020-17065 · Openclinic · Openclinic
Gerben Kleijn
·
Published
2020-12-03
·
Updated
2020-12-07
·
CVE-2020-28939
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClinic version 0.8.2
Description
The issue allows authenticated users with substantial privileges to upload malicious files, such as PHP web shells, to the
medical/test new.php endpoint, which can lead to arbitrary code execution on the application server.Recommendations
For OpenClinic version 0.8.2, consider disabling the file upload functionality in
medical/test new.php until a patch is available to prevent exploitation. Restrict access to this endpoint to minimize the risk of uploading malicious files.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclinic