{"api_version":"1","generated_at":"2026-07-23T08:24:38+00:00","cve":"CVE-2017-5569","urls":{"html":"https://cve.report/CVE-2017-5569","api":"https://cve.report/api/cve/CVE-2017-5569.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5569","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5569"},"summary":{"title":"CVE-2017-5569","description":"An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-01-23 17:59:00","updated_at":"2017-01-26 13:53:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/95741","name":"95741","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"eClinicalWorks Patient Portal CVE-2017-5569 SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dc","name":"https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dc","refsource":"MISC","tags":["Third Party Advisory"],"title":"eClinicalWorks - Patient Portal v7.0 - Blind SQL Injection - pre-authentication - template.jsp · GitHub","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5569","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5569","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5569","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eclinicalworks","cpe5":"patient_portal","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5569","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"eclinicalworks","cpe5":"patient_portal","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5569","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile()."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"95741","refsource":"BID","url":"http://www.securityfocus.com/bid/95741"},{"name":"https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dc","refsource":"MISC","url":"https://gist.github.com/malerisch/d32d127a002ac1f10bce39333ca9a4dc"}]}},"nvd":{"publishedDate":"2017-01-23 17:59:00","lastModifiedDate":"2017-01-26 13:53:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:eclinicalworks:patient_portal:7.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5569","Ordinal":"102118","Title":"CVE-2017-5569","CVE":"CVE-2017-5569","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5569","Ordinal":"1","NoteData":"An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5569","Ordinal":"2","NoteData":"2017-01-23","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5569","Ordinal":"3","NoteData":"2017-01-25","Type":"Other","Title":"Modified"}]}}}