CVE-2020-14493
29.07.2020, 13:15
A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.Enginsight
Vendor | Product | Version |
---|---|---|
openclinic_ga_project | openclinic_ga | 5.09.02 |
openclinic_ga_project | openclinic_ga | 5.89.05b:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-250 - Execution with Unnecessary PrivilegesThe software performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.