OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01 | Third Party Advisory US Government Resource |
https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://us-cert.cisa.gov/ics/advisories/ICSMA-20-184-01 - Third Party Advisory, US Government Resource |
Information
Published : 2020-07-29 13:15
Updated : 2024-11-21 05:03
NVD link : CVE-2020-14490
Mitre link : CVE-2020-14490
CVE.ORG link : CVE-2020-14490
JSON object : View
Products Affected
openclinic_ga_project
- openclinic_ga
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')