An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Apr 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclinic Ga Project
Openclinic Ga Project openclinic Ga |
|
| CPEs | cpe:2.3:a:openclinic_ga_project:openclinic_ga:5.247.01:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclinic Ga Project
Openclinic Ga Project openclinic Ga |
Thu, 10 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclinic
Openclinic ga |
|
| CPEs | cpe:2.3:a:openclinic:ga:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openclinic
Openclinic ga |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-10T20:19:49.003Z
Reserved: 2023-08-14T00:00:00.000Z
Link: CVE-2023-40278
Updated: 2024-08-02T18:31:52.378Z
Status : Analyzed
Published: 2024-03-19T12:15:07.473
Modified: 2025-04-14T13:40:03.483
Link: CVE-2023-40278
No data.
OpenCVE Enrichment
No data.
Weaknesses