Impact
The vulnerability is a classic SQL injection (CWE‑89) that occurs within Mirth Connect's Database Connector API. An authenticated user can supply malicious SQL statements through the API, which are executed against the underlying database. This flaw can be used to read stored credentials on the platform, write arbitrary files, or trigger a denial‑of‑service condition, potentially compromising confidential medical configuration data or disrupting service availability.
Affected Systems
Affected products are NextGen Healthcare’s Mirth Connect platform, specifically versions 4.7.1 and all earlier releases. These versions deploy the vulnerable Database Connector API without proper input validation. Administrators should verify that their Mirth Connect installation falls within this range.
Risk and Exploitability
The CVSS score of 7.2 denotes high severity, and the system requires a legitimate authenticated session to exploit, meaning the attack is most likely to originate from an insider or a compromised user account. Because the EPSS score is not available, it is unclear how frequently attackers have targeted this flaw, but its inclusion in the public advisories suggests it is a known concern. The vulnerability is not currently listed in CISA's KEV catalog. An attacker who gains access could obtain privileged data, alter system files, or cause service disruption, leading to significant operational and data‑security risks.
OpenCVE Enrichment