vendor:
OpenClinic
by:
VB
4.1
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: OpenClinic
Affected Version From: 5.247.01
Affected Version To: 5.247.01
Patch Exists: NO
Related CWE: CVE-2023-40278
CPE: a:openclinic:openclinic:5.247.01
Platforms Tested: Windows 10, Windows 11
2023
OpenClinic GA 5.247.01 – Information Disclosure
An Information Disclosure vulnerability in OpenClinic GA 5.247.01 allows an attacker to infer the existence of specific appointments by manipulating the input to the printAppointmentPdf.jsp component. By observing error messages, an unauthorized user can determine the presence of appointments without direct access to the data, potentially revealing sensitive information about appointments at private clinics, surgeries, and doctors' practices. This vulnerability is identified as CVE-2023-40278.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input to prevent manipulation and ensure that error messages do not leak sensitive information.