Nextgen

Mirth Connect

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 11.09.2026 14:22:29
  • Zuletzt bearbeitet 18.09.2026 19:40:31

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

  • EPSS 0.44%
  • Veröffentlicht 11.09.2026 14:20:06
  • Zuletzt bearbeitet 18.09.2026 19:40:31

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

  • EPSS 0.45%
  • Veröffentlicht 11.09.2026 14:17:24
  • Zuletzt bearbeitet 18.09.2026 19:40:31

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and ...

Warnung Medienbericht Exploit
  • EPSS 82.71%
  • Veröffentlicht 26.10.2023 17:15:09
  • Zuletzt bearbeitet 31.10.2025 14:39:17

NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

Medienbericht Exploit
  • EPSS 99.43%
  • Veröffentlicht 03.08.2023 03:15:10
  • Zuletzt bearbeitet 09.07.2026 01:18:30

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.