[CVE-2020-28937] OpenClinic Version 0.8.2 Advisory
bishopfox.com | blog | CVE-2020-28937 | #rce | #advisory | #file-upload | #missing-authentication | #openclinic | #medical-records | #cve-2020-28937
Summary
Four flaws in OpenClinic 0.8.2: unauthenticated access to patient test results (CVE-2020-28937), RCE via insecure file upload, XSS privilege escalation, and path traversal; no fixed release exists.
- Published
- Collected
Skip to content