First published: Mon May 10 2021(Updated: )
An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openclinic Ga Project Openclinic Ga | =5.173.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2020-27226.
The severity of CVE-2020-27226 is high with a CVSS score of 8.8.
The affected software is OpenClinic GA version 5.173.3.
An SQL injection vulnerability exists in the 'quickFile.jsp' page of OpenClinic GA 5.173.3, which can be exploited via a specially crafted HTTP request.
An attacker can make an authenticated HTTP request to the 'quickFile.jsp' page of OpenClinic GA 5.173.3 to exploit this SQL injection vulnerability.
There is no information available about an official patch or fix for this vulnerability at the time of writing.