VendorsCernermobile_careall versions
Vulnerabilities

Cerner Mobile Care

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2021-36385
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.
Published 2021-08-24 · Modified
10.0EPSS 0.027