CVE Vulnerabilities

CVE-2020-14493

Improper Privilege Management

Published: Jul 29, 2020 | Modified: Jul 30, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Openclinic_ga Openclinic_ga_project 5.09.02 5.09.02
Openclinic_ga Openclinic_ga_project 5.89.05b 5.89.05b

Potential Mitigations

References