VYPR

Openclinic Ga

by Openclinic Ga Project

CVEs (31)

  • CVE-2020-27230HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP…

  • CVE-2020-27229HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2020-27226HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-14490HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.

  • CVE-2021-37364HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a…

  • CVE-2020-27228HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this vulnerability.

  • CVE-2023-40280HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

  • CVE-2020-14491MedJul 20, 2020
    risk 0.42cvss 6.5epss 0.01

    OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.

  • CVE-2023-40277MedMar 19, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter.

  • CVE-2020-14489MedJul 29, 2020
    risk 0.40cvss 6.2epss 0.01

    OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.

  • CVE-2020-14492MedJul 29, 2020
    risk 0.35cvss 5.4epss 0.01

    OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution of malicious code within the user’s browser.

Page 2 of 2