CVE-2020-28938: Openclinic Project Openclinic
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.
Affected products
- Openclinic Project Openclinic: version 0.8.2 only
Published 2020-12-03. Last modified 2026-06-17.