Skip to main content

Vendor archive

eclinicalworks CVEs

Beta · best-effort

8 CVEs tagged to vendor eclinicalworks2 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2017-5599

Published Jan 27, 2017

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5598

Published Jan 27, 2017

An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5570

Published Jan 23, 2017

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5569

Published Jan 23, 2017

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentica…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4594

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it poss…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4593

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authent…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4592

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4591

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1