CVE-2020-28938: Openclinic Project Openclinic

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.

Affected products

Published 2020-12-03. Last modified 2026-06-17.