CVE-2016-6272
HIGHEpic MyChart - XPath Injection via Help Topic Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-6272. PoCs published by Shayan S.
AI-analyzed exploit summary The exploit demonstrates an XPath injection vulnerability in Epic Systems Corporation MyChart via the 'topic' parameter in help.asp. It shows how boolean-based injection can be used to extract information from XML documents.
Description
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.
Exploits (1)
The exploit demonstrates an XPath injection vulnerability in Epic Systems Corporation MyChart via the 'topic' parameter in help.asp. It shows how boolean-based injection can be used to extract information from XML documents.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N