Vulnerabilities (CVE)

Filtered by vendor Eclinicalworks Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4592 1 Eclinicalworks 1 Population Health 2019-03-14 6.5 MEDIUM 8.8 HIGH
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.
CVE-2015-4593 1 Eclinicalworks 1 Population Health 2019-03-14 6.8 MEDIUM 8.8 HIGH
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the creation, modification and deletion of users, appointments and employees.
CVE-2017-5598 1 Eclinicalworks 1 Patient Portal 2017-02-01 5.0 MEDIUM 7.5 HIGH
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.
CVE-2017-5570 1 Eclinicalworks 1 Patient Portal 2017-01-26 6.5 MEDIUM 8.8 HIGH
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().