OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands.
Fixes

Solution

Update to version 5.89.05b or newer.


Workaround

OpenClinic GA is aware of these vulnerabilities but has not provided any confirmation of their resolution. Please upgrade to the latest version to ensure you have all current fixes.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T19:21:13.646Z

Reserved: 2020-06-19T00:00:00

Link: CVE-2020-14487

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-29T14:15:12.583

Modified: 2024-11-21T05:03:22.667

Link: CVE-2020-14487

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.