Vulnerabilities > Freemedsoftware

DATE CVE VULNERABILITY TITLE RISK
2020-07-29 CVE-2020-14488 Unrestricted Upload of File with Dangerous Type vulnerability in Freemedsoftware Openclinic GA 5.09.02/5.89.05B
OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system.
network
low complexity
freemedsoftware CWE-434
critical
9.0
2020-07-29 CVE-2020-14487 Unspecified vulnerability in Freemedsoftware Openclinic GA 5.09.02
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
network
low complexity
freemedsoftware
7.5