ZeroHour

CVE-2023-40278

PoC
CVSS 3.1
7.5 high
EPSS
3%p87
Published
()
Modified
Description

An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.

Vendors
openclinic ga project
Products
openclinic ga
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.