Executive brief
WellSky Harmony, a software platform used by healthcare providers and community-based organizations to manage patient care and social services, contains a critical security flaw in its login system. An attacker can exploit this vulnerability to bypass security checks and gain unauthorized access to the system without needing a valid username or password. This could lead to the exposure of sensitive patient data, unauthorized modification of records, or a complete takeover of the backend database.
Technical details
A SQL injection vulnerability exists in the 'xmHarmony.asp' endpoint of WellSky Harmony version 4.1.0.2.83. The vulnerability is located in the 'TXTUSERID' parameter, which fails to properly sanitize user-supplied input before incorporating it into a SQL query. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests to the login page. Successful exploitation can result in authentication bypass, unauthorized data exfiltration, or full compromise of the backend database contents. As of the advisory date, users should contact the vendor for patching information.
Affected products
- WellSky Harmony 4.1.0.2.83
Timeline
- 2025-11-12: advisory: Initial disclosure of CVE-2025-56385