Executive brief
A security vulnerability has been identified in eClinicalWorks healow@work, a platform used for employee health and wellness management. An unauthorized attacker can exploit this flaw to gain access to sensitive information stored in the application's database. This could lead to the exposure of private employee records or corporate data, potentially resulting in regulatory compliance issues and reputational damage.
Technical details
A blind SQL injection vulnerability exists within the EmployeePortalServlet of eClinicalWorks healow@work 8.0 build 8. The flaw is located in the 'employer' parameter and can be triggered by an unauthenticated user via a specially crafted HTTP POST request. Because it is a blind injection, attackers can use out-of-band techniques, such as the 'select_loadfile()' function, to exfiltrate database contents to an external malicious server. This allows for full data extraction from the underlying database without requiring prior authentication or user interaction.
Affected products
- eClinicalWorks healow@work 8.0 build 8
Timeline
- 2017-01-27: disclosed: Initial NVD publication