CVE-2015-4592

eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclinicalworks:population_health:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:31

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html - Exploit, Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/archive/1/537420/100/0/threaded - Exploit, Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/537420/100/0/threaded - Exploit, Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/39402/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/39402/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-01-10 15:59

Updated : 2024-11-21 02:31


NVD link : CVE-2015-4592

Mitre link : CVE-2015-4592

CVE.ORG link : CVE-2015-4592


JSON object : View

Products Affected

eclinicalworks

  • population_health
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')