Openclinic Project develops a niche healthcare information management system where its disclosed vulnerabilities center on access control and input-handling weaknesses, including direct request exploitability, cross-site scripting, missing authentication and authorization checks, and unrestricted file uploads. Treat this as a focused product profile rather than a broad industry trend; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openclinic Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-20444HIGH Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "c | Jun 16, 2021 | 7.2 | 23 | NO | NO |
CVE-2020-28937HIGH OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in | Dec 3, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-28939HIGH OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to up | Dec 3, 2020 | 7.2 | 22 | NO | NO |
CVE-2020-28938MEDIUM OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users. | Dec 3, 2020 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openclinic Project.
Media articles that mention a CVE ID that affects a product developed by Openclinic Project — matched by CVE ID, not by vendor name.