ZeroHour

CVE-2020-27228

PoC
CVSS 3.1
7.8 high
EPSS
<1%p53
Published
()
Modified
Description

An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this vulnerability.

Vendors
openclinic ga project
Products
openclinic ga
Weakness
CWE-276
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news