Junglewise Threat Intelligence

CVE-2017-5569: eClinicalWorks Patient Portal blind SQL injection in template.jsp

CVE-2017-5569 · Severity: critical · CVSS 9.8 · Published 2017-01-23

Technologies: Eclinicalworks Patient Portal. Vendors: Eclinicalworks.

Executive brief

A critical security vulnerability exists in the eClinicalWorks Patient Portal, a platform used by healthcare providers to share medical records and communicate with patients. An unauthorized attacker can remotely access the underlying database without needing a username or password. This could lead to the theft of sensitive patient information, medical records, and other confidential healthcare data.

Technical details

A blind SQL injection vulnerability exists in the 'template.jsp' component of eClinicalWorks Patient Portal 7.0 build 13. The flaw can be triggered by a remote, unauthenticated attacker sending a specially crafted HTTP POST request. Because the application does not properly sanitize user input before using it in a database query, an attacker can use out-of-band techniques (such as the 'select_loadfile()' function) to exfiltrate data to a server under their control. This allows for full database compromise and unauthorized data extraction.

Affected products

  • eClinicalWorks Patient Portal 7.0 build 13

Timeline

  • 2017-01-23: disclosed
  • 2017-01-23: advisory

References

Related threats