CVE-2020-28937 – OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows …

Vuln ID: CVE-2020-28937

Published:  2020-12-03  16:15:12Z

Description: OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient’s medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.

Source: NVD.NIST.GOV

 


Date:

Categorie(s):

Tag(s):