ZeroHour

CVE-2020-14493

CVSS 3.1
8.8 high
EPSS
2%p76
Published
()
Modified
Description

A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.

Vendors
openclinic ga project
Products
openclinic ga
Weakness
CWE-250, CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.