PoC Index

CVE-2016-6272

HIGH 7.5EPSS 20.9%

XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.

CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
20.88% chance of exploitation in the next 30 days, 97th percentile
Published
2018-02-20
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related