CVE-2020-20444: Openclinic Project Openclinic

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

Affected products

Published 2021-06-16. Last modified 2026-06-17.