PatchSiren cyber security CVE debrief
CVE-2017-5599 Eclinicalworks CVE debrief
CVE-2017-5599 is a reflected cross-site scripting issue in eClinicalWorks Patient Portal 7.0 build 13. The vulnerable raceMasterList.jsp page does not require authentication, and input supplied through the race parameter can be rendered back into the portal. Because the payload is reflected in the browser context, an attacker could use it to target portal users, potentially exposing sensitive information or manipulating browser-side actions.
- Vendor
- Eclinicalworks
- Product
- Patient Portal
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Security teams responsible for eClinicalWorks Patient Portal deployments, web application owners, and administrators who expose raceMasterList.jsp to the internet or broader internal networks should prioritize this issue. It also matters to anyone who relies on the portal for patient-facing workflows, since reflected XSS can affect logged-in users who visit a crafted link.
Technical summary
The NVD record maps this issue to CWE-79 and describes a reflected XSS condition in raceMasterList.jsp for eClinicalWorks Patient Portal 7.0 build 13. The affected page is reachable without authentication, and the race parameter is the injection point noted in the record. The NVD CVSS 3.0 vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, which reflects network reachability, no privileges required, and user interaction needed to trigger the browser-side impact.
Defensive priority
Medium. The CVSS base score is 6.1, and the unauthenticated nature of the vulnerable page increases exposure, especially if the portal is externally reachable.
Recommended defensive actions
- Identify all eClinicalWorks Patient Portal 7.0 build 13 instances and confirm whether raceMasterList.jsp is reachable.
- Treat the race parameter as untrusted input and verify that application output encoding or contextual sanitization is applied on the affected page.
- Apply vendor security updates or remediation guidance if available for the Patient Portal build in use.
- Restrict exposure of the patient portal to trusted networks where feasible until remediation is complete.
- Monitor for unusual portal traffic and user-reported browser pop-ups, redirects, or suspicious links involving raceMasterList.jsp.
- If compensating controls are needed, add web application firewall rules and server-side filtering specific to the affected endpoint while testing a permanent fix.
Evidence notes
The description in the supplied corpus states that this is a reflected XSS vulnerability affecting raceMasterList.jsp in eClinicalWorks Patient Portal 7.0 build 13, that the page does not require authentication, and that the race parameter is involved. The NVD metadata classifies the weakness as CWE-79 and lists CVSS 3.0 vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. References in the record include a SecurityFocus BID entry and a third-party advisory gist; no direct vendor advisory was supplied in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5599 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5599
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5599 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5599
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://gist.github.com/malerisch/8a2c195f385dff7f935db831a8dc2697
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.