#VU29499 Authentication bypass using an alternate path or channel in OpenClinic GA - CVE-2020-14485
Published: July 3, 2020
OpenClinic GA
Frank Verbeke
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exist due to improper implementation of the authentication process. A remote attacker can bypass client-side access controls or use a specially crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries.