PT-2024-12881 · Unknown · Openclinic Ga

Published

2024-03-19

·

Updated

2024-08-01

·

CVE-2023-40278

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClinic GA version 5.247.01
Description An issue has been identified in the printAppointmentPdf.jsp component of OpenClinic GA, which allows an Information Disclosure vulnerability. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
Recommendations For OpenClinic GA version 5.247.01, as a temporary workaround, consider restricting access to the printAppointmentPdf.jsp component until a patch is available. Avoid using the AppointmentUid parameter in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-40278

Affected Products

Openclinic Ga