CVE Published: 29/07/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: icscert |
Vendor: open source |
Product: OpenClinic GA Status : PUBLISHED
CVE-2020-14490 Description
OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files.
Metrics
CVSS Version: 3.1 |
Base Score: 8.8 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H