Vulnerability Description
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclinicalworks | Patient Portal | 7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95741Third Party AdvisoryVDB Entry
- https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dcThird Party Advisory
- http://www.securityfocus.com/bid/95741Third Party AdvisoryVDB Entry
- https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dcThird Party Advisory
FAQ
What is CVE-2017-5569?
CVE-2017-5569 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP ...
How severe is CVE-2017-5569?
CVE-2017-5569 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5569?
Check the references section above for vendor advisories and patch information. Affected products include: Eclinicalworks Patient Portal.