CVE-2020-14490 PUBLISHED CVSS 8.800000190734863 HIGH

OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.

EPSS 0.21% · 42.8th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.21%
42.8th percentile

Affected Products

VendorProductVersions
open sourceOpenClinic GA5.09.02, 5.89.05b
openclinic_ga_projectopenclinic_ga5.09.02, 5.89.05b

Timeline

References

Open in Interactive Console →