PoC Index

CVE-2020-28939

HIGH 7.2EPSS 1.7%

OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.74% chance of exploitation in the next 30 days, 76th percentile
Published
2020-12-03
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related