CVE Vulnerabilities

CVE-2020-14485

Authentication Bypass Using an Alternate Path or Channel

Published: Jul 20, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Openclinic_gaOpenclinic_ga_project5.09.02 (including)5.09.02 (including)
Openclinic_gaOpenclinic_ga_project5.89.05b (including)5.89.05b (including)

Potential Mitigations

References