PT-2026-72151 · Kivicare · Kivicare
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KiviCare – Clinic & Patient Management System (EHR) versions prior to 4.5.2
Description
An issue exists where authenticated attackers with custom-level access and above can perform a generic SQL Injection. This occurs due to insufficient escaping of user-supplied input and a lack of proper preparation of the SQL query. Attackers with a KiviCare custom role possessing the
settings view permission, such as Doctor or Receptionist, can append additional SQL queries to extract sensitive information from the database. The flaw is triggered via the searchTerm parameter.Recommendations
Update the plugin to a version newer than 4.5.1.
Avoid using the
searchTerm parameter if the user has settings view permissions until the update is applied.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kivicare