V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-6272
CVE
HighConfirmedExploit available

XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strin…

CVSS
7.5
High
EPSS
0.06
p90
Published
2016-01-01
Updated
2016-01-01
Description

XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.

Tags · CWE
Pre-auth
CWE-91
CAPEC-83
CAPEC-250
Affected products
Mychart
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.065 · p90
Known exploited (KEV)
No
Known exploits — Сканер-ВС
44098
exploitdb · https://www.exploit-db.com/exploits/44098
Enterprise
Affected software
ProductVendorStatus
mychart*Tracked
Source databases
CVE