cvedb.io
CVE-2017-5599
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2017-01-27T10:59:00.193 · Last modified 2026-06-17T01:20:48.947

Summary

An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the Patient Portal. Inserted payload is rendered within the Patient Portal and the raceMasterList.jsp page does not require authentication. The vulnerability can be used to extract sensitive information or perform attacks against the user's browser. The vulnerability affects the raceMasterList.jsp page and the following parameter: race.

Affected products

eclinicalworks — patient_portal

Does this affect you?

Add your gear to cvedb and we'll alert you only when eclinicalworks ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.