CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Openclinic Project 1Openclinic Nov 21, 2024 Jun 16, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability . |
1Openclinic Project 1Openclinic Jun 17, 2026 Dec 3, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web sh...Show more |
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users. |
1Openclinic Project 1Openclinic Jun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Informat...Show more |