CVE-2022-24830
Path Traversal in OpenClinica
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 2.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
13 May 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There are no known workarounds. This issue has been patched and users are recommended to upgrade.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
OpenClinica · OpenClinicaWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →