eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.
Publication date: Tue, 10 Jan 2017 21:59:00 +0000