CVE-2020-27227

CRITICAL

OpenClinic GA 5.173.3 - Command Injection

Title source: llm
STIX 2.1

Description

An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and compromise underlying operating system.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1203

Scores

CVSS v3 9.8
EPSS 0.0289
EPSS Percentile 85.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
openclinic_ga_project/openclinic_ga 5.173.3
Published Apr 13, 2021
Tracked Since Feb 18, 2026