Executive brief
A critical security vulnerability exists in the eClinicalWorks Patient Portal, a platform used by healthcare providers to share medical records and communicate with patients. An unauthorized attacker can remotely access the underlying database without needing a username or password. This could lead to the theft of sensitive patient information, medical records, and other confidential healthcare data.
Technical details
A blind SQL injection vulnerability exists in the 'template.jsp' component of eClinicalWorks Patient Portal 7.0 build 13. The flaw can be triggered by a remote, unauthenticated attacker sending a specially crafted HTTP POST request. Because the application does not properly sanitize user input before using it in a database query, an attacker can use out-of-band techniques (such as the 'select_loadfile()' function) to exfiltrate data to a server under their control. This allows for full database compromise and unauthorized data extraction.
Affected products
- eClinicalWorks Patient Portal 7.0 build 13
Timeline
- 2017-01-23: disclosed
- 2017-01-23: advisory