Vulnerabilities > CVE-2020-14491 - Missing Authorization vulnerability in Openclinic GA Project Openclinic GA 5.09.02/5.89.05B

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
openclinic-ga-project
CWE-862

Summary

OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.

Common Weakness Enumeration (CWE)