PT-2026-57379 · Kivicare · Kivicare
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KiviCare – Clinic & Patient Management System (EHR) versions prior to 4.5.1
Description
An issue exists where authenticated attackers with doctor-level access or higher (including Receptionist or Clinic Admin roles with the
doctor session list capability) can perform a generic SQL Injection. This occurs due to insufficient escaping of the user-supplied orderby parameter and a lack of proper preparation of the SQL query. This flaw allows attackers to append additional SQL queries to existing ones to extract sensitive information from the database.Recommendations
Update to a version newer than 4.5.0.
Avoid using the
orderby parameter until the system is updated.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kivicare