eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the creation, modification and deletion of users, appointments and employees.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-01-10T15:00:00

Updated: 2018-10-09T18:57:01

Reserved: 2015-06-16T00:00:00


Link: CVE-2015-4593

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-01-10T15:59:00.250

Modified: 2019-03-14T00:57:58.353


Link: CVE-2015-4593

JSON object: View

cve-icon Redhat Information

No data.

CWE