vendor:
MyChart
by:
Shayan Sadigh
7.5
CVSS
HIGH
X-Path Injection
89
CWE
Product Name: MyChart
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2016-6272
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Unix
2016
Epic Systems Corporation MyChart X-Path Injection
The MyChart software contains an X-Path injection due to the lack of sanitization for the GE parameter 'topic'. A remote attacker can access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp.
Mitigation:
EPIC was quick to respond to contact and patch the vulnerability in MyChart.