Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pxxg-w7cj-99fp

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

EPSS

Процентиль: 70%
0.00634
Низкий

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

EPSS

Процентиль: 70%
0.00634
Низкий

Дефекты

CWE-287