← back
CVE-2023-40278

CVE-2023-40278

CVSS 7.5 HIGHEPSS 3.0%CWE-200
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.5EPSS 3.0%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
19 Mar 2024Published on NVD
15 Apr 2024Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →