CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Eclinicalworks 1Population Health May 6, 2026 Jan 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID. |
1Eclinicalworks 1Population Health May 6, 2026 Jan 10, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for req...Show more |
1Eclinicalworks 1Population Health May 6, 2026 Jan 10, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input. |
1Eclinicalworks 1Population Health May 6, 2026 Jan 10, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter. |