OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-07-29 06:15
Updated : 2020-07-30 09:11
NVD link : CVE-2020-14490
Mitre link : CVE-2020-14490
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
openclinic_ga_project
- openclinic_ga