Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
{
"extracted_events": [
{
"introduced": "0.8.20160412"
},
{
"last_affected": "0.8.20160412"
}
],
"source": "CPE_STRING",
"cpe": "cpe:2.3:a:openclinic_project:openclinic:0.8.20160412:*:*:*:*:*:*:*"
}