← back
CVE-2023-40278highCWE-200

CVE-2023-40278

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.5epss 3.0%
from disclosure to weapon27 days
Published on NVDMar 19
1st PoC+27d
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.