NA

CVE-2023-40278

Published: 19/03/2024 Updated: 19/03/2024

Vulnerability Summary

An issue exists in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.

Exploits

OpenClinic GA version 524701 suffers from an information disclosure vulnerability ...