PT-2024-12879 · Unknown · Openclinic Ga

Published

2024-03-18

·

Updated

2024-08-29

·

CVE-2023-40276

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClinic GA version 5.247.01
Description An Unauthenticated File Download issue has been discovered in the pharmacy/exportFile.jsp file. This allows unauthorized access to sensitive files.
Recommendations For OpenClinic GA version 5.247.01, restrict access to the pharmacy/exportFile.jsp file to prevent unauthorized file downloads until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-40276

Affected Products

Openclinic Ga