Vulnerabilities > CVE-2020-20444 - Missing Authorization vulnerability in Openclinic Project Openclinic 0.8.20160412

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
openclinic-project
CWE-862

Summary

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

Vulnerable Configurations

Part Description Count
Application
Openclinic_Project
1

Common Weakness Enumeration (CWE)