CVE Feed

    Dashboard / CVE / CVE-2022-24830

    CVE-2022-24830

    OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There are no known workarounds. This issue has been patched and users are recommended to upgrade.

    Published:May 13, 2022
    Last Modified:Apr 22, 2025
    EPS:May 13, 2022
    EPSS Score:0.0191
    CVSS Score:6.5

    Affected Products

    Vendor
    Openclinica
    Product
    Openclinica

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High