CVE-2017-5598 Information
Feb 14, 2021
cve
Description
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server using an out-of-band technique such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
http://www.securityfocus.com/bid/95836 https://gist.github.com/malerisch/ded4d6e6e980667ee9f7fc7f2818f4fa
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.5
Share on: