An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.
References
Configurations
History
No history.
Information
Published : 2024-03-19 13:15
Updated : 2025-04-14 13:40
NVD link : CVE-2023-40279
Mitre link : CVE-2023-40279
CVE.ORG link : CVE-2023-40279
JSON object : View
Products Affected
openclinic_ga_project
- openclinic_ga
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
