← Back to CVE List

CVE-2016-6272

Published: 2018-02-20T15:29Z
Last Modified: 2024-11-21T02:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt