CVE-2020-14489
MEDIUMOpenclinic GA - Insufficiently Protected Credentials
Title source: ruleDescription
OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.
Scores
CVSS v3
6.2
EPSS
0.0012
EPSS Percentile
31.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-522
Status
published
Affected Products (2)
openclinic_ga_project/openclinic_ga
openclinic_ga_project/openclinic_ga
Timeline
Published
Jul 29, 2020
Tracked Since
Feb 18, 2026