CVE-2015-4591
MEDIUMEclinicalworks Population Health - XSS
Title source: ruleDescription
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.
Exploits (1)
References (3)
Scores
CVSS v3
6.1
EPSS
0.0226
EPSS Percentile
84.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
eclinicalworks/population_health
n/a/n/a
Timeline
Published
Jan 10, 2017
Tracked Since
Feb 18, 2026