PT-2026-72151 · Kivicare · Kivicare

·

CVE-2026-15453

·

Published

2026-08-15

·

Updated

2026-08-20

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions KiviCare – Clinic & Patient Management System (EHR) versions prior to 4.5.2
Description An issue exists where authenticated attackers with custom-level access and above can perform a generic SQL Injection. This occurs due to insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query. Attackers with a KiviCare custom role possessing the settings view permission, such as Doctor or Receptionist, can append additional SQL queries to extract sensitive information from the database. The flaw is triggered via the searchTerm parameter.
Recommendations Update the plugin to a version newer than 4.5.1. Avoid using the searchTerm parameter if the user has settings view permissions until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15453

Affected Products

Kivicare