ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-27227”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-27227
Published
2021-04-13
CVSS:
10.0
ShadowTrackr CVSS:
7.2
Summary:
An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and compromise underlying operating system.