CVE-2020-14493

HIGH

OpenClinic GA <5.89.05b - SQL Injection

Title source: llm
STIX 2.1

Description

A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.

Scores

CVSS v3 8.8
EPSS 0.0047
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269 CWE-250
Status published
Products (2)
openclinic_ga_project/openclinic_ga 5.09.02
openclinic_ga_project/openclinic_ga 5.89.05b
Published Jul 29, 2020
Tracked Since Feb 18, 2026