First published: Wed Jun 16 2021(Updated: )
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenClinic GA | =0.8.20160412 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20444 is a vulnerability in Jact OpenClinic 0.8.20160412 that allows an attacker to read server files after logging in to the admin account.
CVE-2020-20444 works by exploiting an infected 'file' GET parameter in '/shared/view_source.php' which could lead to remote code execution vulnerability.
The severity of CVE-2020-20444 is high with a CVSS score of 7.2.
CVE-2020-20444 affects Jact OpenClinic 0.8.20160412.
To fix CVE-2020-20444, users should update to a patched version of Jact OpenClinic that addresses this vulnerability.