Openclinic GA Project
Openclinic GA Project Openclinic GA: vulnerabilidades y CVE
Openclinic GA Project Openclinic GA tiene 37 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses0
Críticas15
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-40279 | Alta (7.5) | 3.4% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do. |
| CVE-2023-40278 | Alta (7.5) | 3.0% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an… |
| CVE-2023-40280 | Alta (7.5) | 0.85% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp. |
| CVE-2023-40277 | Media (6.1) | 0.45% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. A Reflected Cross-Site Scripting (XSS) vulnerability has been discovered in the login.jsp message parameter. |
| CVE-2023-40276 | Crítica (9.1) | 0.74% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp. |
| CVE-2023-40275 | Crítica (9.1) | 0.92% | — | 19 mar 2024 | An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp. |
| CVE-2021-37364 | Alta (7.8) | 1.3% | — | 26 oct 2021 | OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or… |
| CVE-2020-27246 | Alta (8.8) | 0.81% | — | 11 may 2021 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL… |
| CVE-2020-27245 | Alta (8.8) | 0.81% | — | 11 may 2021 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection.… |
| CVE-2020-27244 | Alta (8.8) | 0.81% | — | 11 may 2021 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection.… |
| CVE-2020-27243 | Alta (8.8) | 0.81% | — | 11 may 2021 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL… |
| CVE-2020-27242 | Alta (8.8) | 0.81% | — | 11 may 2021 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL… |
| CVE-2020-27232 | Alta (8.8) | 1.0% | — | 10 may 2021 | An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP… |
| CVE-2020-27231 | Alta (8.8) | 0.81% | — | 10 may 2021 | A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL… |
| CVE-2020-27230 | Alta (8.8) | 0.81% | — | 10 may 2021 | A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL… |
| CVE-2020-27229 | Alta (8.8) | 0.81% | — | 10 may 2021 | A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL… |
| CVE-2020-27226 | Alta (8.8) | 1.0% | — | 10 may 2021 | An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to… |
| CVE-2020-27241 | Crítica (9.8) | 0.87% | — | 19 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can… |
| CVE-2020-27240 | Crítica (9.8) | 0.87% | — | 19 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can… |
| CVE-2020-27239 | Crítica (9.8) | 0.87% | — | 15 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make… |
| CVE-2020-27238 | Crítica (9.8) | 0.87% | — | 15 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an… |
| CVE-2020-27237 | Crítica (9.8) | 0.87% | — | 15 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL… |
| CVE-2020-27236 | Crítica (9.8) | 0.88% | — | 13 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2020-27235 | Crítica (9.8) | 0.88% | — | 13 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2020-27234 | Crítica (9.8) | 0.88% | — | 13 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2020-27233 | Crítica (9.8) | 0.88% | — | 13 abr 2021 | An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
| CVE-2020-27228 | Alta (7.8) | 0.76% | — | 13 abr 2021 | An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this… |
| CVE-2020-27227 | Crítica (9.8) | 2.9% | — | 13 abr 2021 | An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters… |
| CVE-2020-14486 | Alta (8.8) | 1.3% | — | 29 jul 2020 | An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands. |
| CVE-2020-14493 | Alta (8.8) | 1.7% | — | 29 jul 2020 | A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands. |