VYPR

Openclinica

by Openclinica

CVEs (47)

  • CVE-2020-27242HigMay 11, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2020-27232HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-27231HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2020-27230HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP…

  • CVE-2020-27229HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP…

  • CVE-2020-27226HigMay 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2020-14488HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system.

  • CVE-2020-14493HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.

  • CVE-2020-14490HigJul 29, 2020
    risk 0.57cvss 8.8epss 0.02

    OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.

  • CVE-2023-40279HigMar 19, 2024
    risk 0.52cvss 7.5epss 0.03

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.

  • CVE-2023-40278HigMar 19, 2024
    risk 0.52cvss 7.5epss 0.03

    An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists…

  • CVE-2021-37364HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a…

  • CVE-2020-27228HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this vulnerability.

  • CVE-2023-40280HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.

  • CVE-2020-28937HigDec 3, 2020
    risk 0.49cvss 7.5epss 0.01

    OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request…

  • CVE-2020-28939HigDec 3, 2020
    risk 0.47cvss 7.2epss 0.02

    OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the…

  • CVE-2020-14491MedJul 20, 2020
    risk 0.42cvss 6.5epss 0.01

    OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.

  • CVE-2025-12922MedNov 10, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /ImportCRFData?action=confirm of the component CRF Data Import. Performing manipulation of the argument xml_file results in path traversal. The attack can be…

  • CVE-2020-14486MedJul 29, 2020
    risk 0.41cvss 6.3epss 0.01

    An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands.

  • CVE-2026-25860MedJun 9, 2026
    risk 0.40cvss 6.1epss 0.00

    OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM…