Vulnerability CVE-2016-6272


Published: 2018-02-20

Description:
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
EPIC MyChart SQL Injection
Shayan S
17.02.2018

Type:

CWE-91

(XML Injection (aka Blind XPath Injection))

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
EPIC -> Mychart 

 References:
http://packetstormsecurity.com/files/146418/EPIC-MyChart-SQL-Injection.html
https://www.exploit-db.com/exploits/44098/

Copyright 2024, cxsecurity.com

 

Back to Top