Junglewise Threat Intelligence

CVE-2017-5570: eClinicalWorks Patient Portal blind SQL injection in messageJson.jsp

CVE-2017-5570 · Severity: high · CVSS 8.8 · Published 2017-01-23

Technologies: Eclinicalworks Patient Portal. Vendors: Eclinicalworks.

Executive brief

A security vulnerability exists in the eClinicalWorks Patient Portal, a platform used by healthcare providers to share medical records and communicate with patients. An authorized user, such as a patient, could exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive medical records or other private patient information.

Technical details

A blind SQL injection vulnerability exists in the messageJson.jsp component of eClinicalWorks Patient Portal 7.0 build 13. The flaw is triggered via a specially crafted HTTP POST request. While authentication is required for exploitation, a low-privileged user can leverage out-of-band techniques, such as the select_loadfile() function, to exfiltrate database contents to an external malicious server. This allows for full compromise of data confidentiality, integrity, and availability within the affected database instance.

Affected products

  • eClinicalWorks Patient Portal 7.0 build 13

Timeline

  • 2017-01-23: disclosed
  • 2017-01-23: advisory

References

Related threats