High severity8.3NVD Advisory· Published May 14, 2022· Updated Jun 17, 2026
CVE-2022-24831
CVE-2022-24831
Description
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds exist. This issue has been patched in 3.16.1, 3.15.9, 3.14.1, and 3.13.1 and users are advised to upgrade.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4< 3.13.1+ 3 more
- (no CPE)range: < 3.13.1
- (no CPE)range: <3.16.1
- cpe:2.3:a:openclinica:openclinica:*:*:*:*:*:*:*:*range: <3.13.1
- cpe:2.3:a:openclinica:openclinica:3.14:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- github.com/OpenClinica/OpenClinica/pull/3490/commits/b152cc63019230c9973965a98e4386ea5322c18fnvdPatchThird Party Advisory
- github.com/OpenClinica/OpenClinica/security/advisories/GHSA-5289-4jwp-xp9hnvdPatchThird Party Advisory
News mentions
0No linked articles in our index yet.