github.com
https://github.com/BugBountyHunterCVE/CVE-2023-40278/blob/main/CVE-2023-40278_Information-Disclosure_OpenClinic-GA_5.247.01_Report.md CVE-2023-40278
HIGH
OpenClinic GA 5.247.01 - Information Disclosure
Record summary
CVE-2023-40278 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 20, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 5.247.01 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBOpenClinic GA 5.247.01 - Information DisclosureExploitDB exploitby VBNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-40278 sourceforge.net
https://sourceforge.net/projects/open-clinic