A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2020-07-29T12:27:28.691565Z

Updated: 2024-09-17T03:13:05.119Z

Reserved: 2020-06-19T00:00:00

Link: CVE-2020-14493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-29T13:15:10.260

Modified: 2024-11-21T05:03:23.433

Link: CVE-2020-14493

cve-icon Redhat

No data.