Eclinicalworks develops electronic health record and patient engagement platforms deployed across clinical workflows, with a focused product portfolio centered on its patient portal and population health management offerings. Vulnerabilities affecting the vendor skew toward serious outcomes, frequently acquire public exploit code, and concentrate in web-application and access-control weakness classes including SQL injection, cross-site scripting, cross-site request forgery, and improper access control—exposures characteristic of internet-facing healthcare software handling sensitive patient data. Defenders should prioritize this vendor's advisories for internet-connected deployments and treat authentication and input-handling disclosures as high-urgency; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eclinicalworks over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4594CRITICAL eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possi | Jan 10, 2017 | 9.8 | 36 | NO | YES |
CVE-2015-4593HIGH eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authenti | Jan 10, 2017 | 8.8 | 32 | NO | YES |
CVE-2015-4592HIGH eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious d | Jan 10, 2017 | 8.8 | 32 | NO | YES |
CVE-2017-5570HIGH An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users | Jan 23, 2017 | 8.8 | 28 | NO | NO |
CVE-2015-4591MEDIUM eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via | Jan 10, 2017 | 6.1 | 28 | NO | YES |
CVE-2017-5598HIGH An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users | Jan 27, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-5569CRITICAL An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authenticat | Jan 23, 2017 | 9.8 | 24 | NO | NO |
CVE-2017-5599MEDIUM An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the P | Jan 27, 2017 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eclinicalworks.
Media articles that mention a CVE ID that affects a product developed by Eclinicalworks — matched by CVE ID, not by vendor name.