CVE-2016-6272

HIGH

Epic MyChart - XPath Injection via Help Topic Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-6272. PoCs published by Shayan S.

AI-analyzed exploit summary The exploit demonstrates an XPath injection vulnerability in Epic Systems Corporation MyChart via the 'topic' parameter in help.asp. It shows how boolean-based injection can be used to extract information from XML documents.

Description

XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shayan S · textwebappsasp
https://www.exploit-db.com/exploits/44098

The exploit demonstrates an XPath injection vulnerability in Epic Systems Corporation MyChart via the 'topic' parameter in help.asp. It shows how boolean-based injection can be used to extract information from XML documents.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Epic Systems Corporation MyChart (version not specified)
No auth needed
Prerequisites: Access to the MyChart help.asp endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44098/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/146418/EPIC-MyChart-SQL-Injection.html

Scores

CVSS v3 7.5
EPSS 0.2166
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-91
Status published
Products (1)
epic/mychart
Published Feb 20, 2018
Tracked Since Feb 18, 2026