Impact
The vulnerability exists in Mirth Connect when XML batch processing is enabled and the XPath option is selected. In this configuration, raw XML input is processed by a default XPath/JAXP setup that does not enforce entity restrictions. This permits XML External Entity (XXE) injection, allowing an attacker to read arbitrary files from the server, exfiltrate sensitive data, or cause denial-of-service conditions by exploiting resource exhaustion or malformed input.
Affected Systems
All installations of NextGen Healthcare Mirth Connect that are running a version earlier than v4.7.2 are affected. No version information beyond the fact that prior releases lack the patch is provided.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker submitting a crafted XML batch file or job that includes a malicious external entity reference. Successful exploitation could result in data leakage and service interruption. No mitigation is provided by the product out of the box in those versions, so the risk persists until the fix is applied.
OpenCVE Enrichment