CVE Published: 29/07/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: icscert |
Vendor: open source |
Product: OpenClinic GA Status : PUBLISHED
CVE-2020-14487 Description
OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
Metrics
CVSS Version: 3.1 |
Base Score: 9.4 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L