CVE-2015-4592 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.35% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-01-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| eclinicalworks | population health |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | eClinicalWorks (CCMR) - Multiple Vulnerabilities | 2016-02-02 |
References
- http://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html
- http://www.securityfocus.com/archive/1/537420/100/0/threaded
- https://www.exploit-db.com/exploits/39402/
- http://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html
- http://www.securityfocus.com/archive/1/537420/100/0/threaded
- https://www.exploit-db.com/exploits/39402/
→ the Explorer · watch your stack · NVD