2024-12-08 03:06:42 +00:00

72 lines
2.5 KiB
JSON

{
"id": "CVE-2023-40278",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-03-19T12:15:07.473",
"lastModified": "2024-11-21T08:19:07.123",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in OpenClinic GA 5.247.01. An Information Disclosure vulnerability has been identified in the printAppointmentPdf.jsp component of OpenClinic GA. By changing the AppointmentUid parameter, an attacker can determine whether a specific appointment exists based on the error message."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema en OpenClinic GA 5.247.01. Se ha identificado una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n en el componente printAppointmentPdf.jsp de OpenClinic GA. Al cambiar el par\u00e1metro AppointmentUid, un atacante puede determinar si existe una cita espec\u00edfica en funci\u00f3n del mensaje de error."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"references": [
{
"url": "https://github.com/BugBountyHunterCVE/CVE-2023-40278/blob/main/CVE-2023-40278_Information-Disclosure_OpenClinic-GA_5.247.01_Report.md",
"source": "cve@mitre.org"
},
{
"url": "https://sourceforge.net/projects/open-clinic/",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/BugBountyHunterCVE/CVE-2023-40278/blob/main/CVE-2023-40278_Information-Disclosure_OpenClinic-GA_5.247.01_Report.md",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://sourceforge.net/projects/open-clinic/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
]
}