Junglewise Threat Intelligence

CVE-2017-5599: eClinicalWorks Patient Portal reflected XSS in raceMasterList.jsp

CVE-2017-5599 · Severity: medium · CVSS 6.1 · Published 2017-01-27

Technologies: Eclinicalworks Patient Portal. Vendors: Eclinicalworks.

Executive brief

A security vulnerability exists in the eClinicalWorks Patient Portal, a platform used by healthcare providers to share medical information with patients. An attacker could use this flaw to run malicious scripts in a patient's web browser if they click a specifically crafted link. This could lead to the theft of sensitive medical information or unauthorized access to the patient's account.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in eClinicalWorks Patient Portal 7.0 build 13. The vulnerability is located in the 'race' parameter of the raceMasterList.jsp page, which fails to properly sanitize user-supplied input before rendering it in the response. Because this page does not require authentication, a remote attacker can craft a malicious URL and trick a user into clicking it. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or the exfiltration of sensitive data displayed within the portal.

Affected products

  • eClinicalWorks Patient Portal 7.0 build 13

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory

References

Related threats