OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.
References
Link | Resource |
---|---|
https://labs.bishopfox.com/advisories/openclinic-version-0.8.2 | Exploit Third Party Advisory |
https://labs.bishopfox.com/advisories/openclinic-version-0.8.2 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 05:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://labs.bishopfox.com/advisories/openclinic-version-0.8.2 - Exploit, Third Party Advisory |
Information
Published : 2020-12-03 16:15
Updated : 2024-11-21 05:23
NVD link : CVE-2020-28939
Mitre link : CVE-2020-28939
CVE.ORG link : CVE-2020-28939
JSON object : View
Products Affected
openclinic_project
- openclinic
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type