PT-2022-16908 · Unknown · Openclinic Ga

Jlleitschuh

·

Published

2022-05-13

·

Updated

2022-05-24

·

CVE-2022-24830

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenClinica versions prior to 3.16
Description OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). It is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There are no known workarounds.
Recommendations For OpenClinica versions prior to 3.16, upgrade to version 3.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoints to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24830
GHSA-9RRV-PRFF-QPH7

Affected Products

Openclinic Ga