OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openclinic_ga | Openclinic_ga_project | 5.09.02 (including) | 5.09.02 (including) |
Openclinic_ga | Openclinic_ga_project | 5.89.05b (including) | 5.89.05b (including) |