An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message.
History

Mon, 14 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openclinic Ga Project
Openclinic Ga Project openclinic Ga
CPEs cpe:2.3:a:openclinic_ga_project:openclinic_ga:5.247.01:*:*:*:*:*:*:*
Vendors & Products Openclinic Ga Project
Openclinic Ga Project openclinic Ga

Thu, 10 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Openclinic
Openclinic ga
CPEs cpe:2.3:a:openclinic:ga:*:*:*:*:*:*:*:*
Vendors & Products Openclinic
Openclinic ga
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-19T00:00:00.000Z

Updated: 2025-04-10T20:19:49.003Z

Reserved: 2023-08-14T00:00:00.000Z

Link: CVE-2023-40278

cve-icon Vulnrichment

Updated: 2024-08-02T18:31:52.378Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-19T12:15:07.473

Modified: 2025-04-14T13:40:03.483

Link: CVE-2023-40278

cve-icon Redhat

No data.