Vulnerability CVE-2015-4591


Published: 2017-01-10

Description:
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
eClinicalWorks Population Health (CCMR) SQL Injection / CSRF / XSS
Jerold Hoong
02.02.2016

Vendor: Eclinicalworks
Product: Population health 

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None

 References:
http://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html
http://www.securityfocus.com/archive/1/archive/1/537420/100/0/threaded
https://www.exploit-db.com/exploits/39402/

Related CVE
CVE-2015-4593
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the c...
CVE-2015-4594
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.
CVE-2015-4592
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.

Copyright 2017, cxsecurity.com