CVE-2020-27245
11.05.2021, 11:15
An exploitable SQL injection vulnerability exists in listImmoLabels.jsp page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the listImmoLabels.jsp page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Vendor | Product | Version |
---|---|---|
openclinic_ga_project | openclinic_ga | 5.173.3 |
𝑥
= Vulnerable software versions