Impact
The vulnerability occurs because the XSLT Transformer Step creates a bare TransformerFactory without the necessary security options, exposing the system to XXE injection. This flaw permits an attacker to craft specially crafted XML that can read arbitrary files or data from the server, leading to confidential information leakage, and can also trigger excessive resource consumption that can crash the application, resulting in denial‑of‑service.
Affected Systems
NextGen Healthcare’s Mirth Connect is affected. All releases prior to 4.7.2 are vulnerable, and the vendor recommends upgrading to version 4.7.2 or later through the customer portal.
Risk and Exploitability
The CVSS score of 8.8 classifies this as high severity, and although the EPSS score is not available, the lack of a KEV listing suggests it is not yet widely exploited in the wild. The vulnerability is likely exploitable through remote XML input that reaches the XSLT transformer, making it available to attackers who can submit malicious XML documents over the network.
OpenCVE Enrichment