Executive brief
A security vulnerability exists in the eClinicalWorks Patient Portal, a platform used by healthcare providers to share medical records and communicate with patients. An authorized user, such as a patient, could exploit this flaw to gain unauthorized access to the underlying database. This could lead to the theft of sensitive medical records or other private patient information.
Technical details
A blind SQL injection vulnerability exists in the messageJson.jsp component of eClinicalWorks Patient Portal 7.0 build 13. The flaw is triggered via a specially crafted HTTP POST request. While authentication is required for exploitation, a low-privileged user can leverage out-of-band techniques, such as the select_loadfile() function, to exfiltrate database contents to an external malicious server. This allows for full compromise of data confidentiality, integrity, and availability within the affected database instance.
Affected products
- eClinicalWorks Patient Portal 7.0 build 13
Timeline
- 2017-01-23: disclosed
- 2017-01-23: advisory