CVE-2017-5569

CRITICAL

eClinicalWorks Patient Portal 7.0 build 13 - Unauthenticated Blind SQL Injection via template.jsp

Title source: llm
STIX 2.1

Description

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95741

Scores

CVSS v3 9.8
EPSS 0.0200
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
eclinicalworks/patient_portal 7.0
Published Jan 23, 2017
Tracked Since Feb 18, 2026