CVE-2017-5569
This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.00% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- eclinicalworks/patient portal
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/95741Third Party Advisory, VDB Entry
- https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dcThird Party Advisory
- http://www.securityfocus.com/bid/95741Third Party Advisory, VDB Entry
- https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dcThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.