jact/openclinic

jact/openclinic

Releases22
Frequency6 months 2 weeks
Last Release
Stars40
OpenClinic is an easy to use, open source, medical records system written in PHP.

CVE History

CVEPublishedCVSS v3CVSS v2
7.2 HIGH6.5 MEDIUM

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .