myCare2x CMS – Multiple Web Vulnerabilities
The Vulnerability Laboratory Researcher Team discovered multiple web vulnerabilities in myCare v2x CMS. Multiple remote SQL Injection vulnerabilities are detected in myCare2x Content Management System. The vulnerability allows an attacker (remote) or local low privileged user account to inject/execute own sql commands on the affected application dbms. Successful exploitation of the vulnerability results in dbms & application compromise. The vulnerability is located on the username post method. Multiple persistent input validation vulnerabilites are detected in myCare2x Content Management System. The vulnerability allows remote attackers to inject/execute malicious script code on the application-side (persistent). Successful exploitation of the vulnerability results in account steal, session hijacking, persistent phishing attacks, persistent external redirects and more.