Vulnerability Description
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclinic Project | Openclinic | 0.8.20160412 |
Related Weaknesses (CWE)
References
- https://cwe.mitre.org/data/definitions/23.htmlTechnical Description
- https://github.com/jact/openclinic/issues/8ExploitIssue TrackingPatch
- https://cwe.mitre.org/data/definitions/23.htmlTechnical Description
- https://github.com/jact/openclinic/issues/8ExploitIssue TrackingPatch
FAQ
What is CVE-2020-20444?
CVE-2020-20444 is a vulnerability with a CVSS score of 7.2 (HIGH). Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vu...
How severe is CVE-2020-20444?
CVE-2020-20444 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-20444?
Check the references section above for vendor advisories and patch information. Affected products include: Openclinic Project Openclinic.