📦 Openclinic Ga

by Openclinic Ga Project

🔍 What is Openclinic Ga?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-40275

CRITICAL CVSS 9.1 Mar 19, 2024

This vulnerability in OpenClinic GA allows unauthenticated attackers to retrieve patient lists via direct API queries to searchByAjax/patientslistShow.jsp. It affects OpenClinic GA installations, expo...

CVE-2020-27240

CRITICAL CVSS 9.8 Apr 19, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems through the componentStatus parameter in getAssets.jsp. Successful exploitation could lea...

CVE-2020-27237

CRITICAL CVSS 9.8 Apr 15, 2021

This vulnerability allows unauthenticated SQL injection attacks against OpenClinic GA's getAssets.jsp page via the nomenclature parameter. Attackers can execute arbitrary SQL commands to potentially a...

CVE-2020-27239

CRITICAL CVSS 9.8 Apr 15, 2021

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems via the assetStatus parameter in getAssets.jsp. Successful exploitation could lead to com...

CVE-2020-27235

CRITICAL CVSS 9.8 Apr 13, 2021

This is an authenticated SQL injection vulnerability in OpenClinic GA's 'getAssets.jsp' page that allows attackers to execute arbitrary SQL commands through the description parameter. Attackers with v...

CVE-2020-27227

CRITICAL CVSS 9.8 Apr 13, 2021

CVE-2020-27227 is an unauthenticated command injection vulnerability in OpenClinic GA that allows remote attackers to execute arbitrary commands on the server. This affects OpenClinic GA version 5.173...

CVE-2020-27233

CRITICAL CVSS 9.8 Apr 13, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the supplierUID parameter in OpenClinic GA's getAssets.jsp page. Successful exploitation could lead to data ...

CVE-2023-40278

HIGH CVSS 7.5 Mar 19, 2024

This vulnerability in OpenClinic GA allows attackers to determine whether specific appointments exist by manipulating the AppointmentUid parameter in the printAppointmentPdf.jsp component. The system ...

CVE-2023-40280

HIGH CVSS 7.5 Mar 19, 2024

This vulnerability allows authenticated attackers to perform directory path traversal attacks in OpenClinic GA by manipulating the Page parameter in GET requests to popup.jsp. This could enable unauth...

CVE-2021-37364

HIGH CVSS 7.8 Oct 26, 2021

OpenClinic GA 5.194.18 has insecure file permissions that allow authenticated low-privilege users to replace critical service executables with malicious files. When the system restarts, these maliciou...

CVE-2020-27242

HIGH CVSS 8.8 May 11, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems. Attackers with valid credentials can exploit the SQL injection in the 'listImmoLabels.jsp'...

CVE-2020-27244

HIGH CVSS 8.8 May 11, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the 'immoCode' parameter in OpenClinic GA's listImmoLabels.jsp page. Successful exploitation could lead to d...

CVE-2020-27246

HIGH CVSS 8.8 May 11, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands on OpenClinic GA systems through the 'listImmoLabels.jsp' page. Attackers can potentially access, modify, or delete ...

CVE-2020-27232

HIGH CVSS 8.8 May 10, 2021

This SQL injection vulnerability in OpenClinic GA's 'manageServiceStocks.jsp' page allows authenticated attackers to execute arbitrary SQL commands. Attackers could potentially read, modify, or delete...

CVE-2020-27229

HIGH CVSS 8.8 May 10, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the 'findPersonID' parameter in OpenClinic GA's patientslist.do page. Successful exploitation could lead to ...

CVE-2020-27231

HIGH CVSS 8.8 May 10, 2021

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the 'findDistrict' parameter in OpenClinic GA's patientslist.do page. Successful exploitation could lead to ...