CVE-2012-4260: Hccgmbh MYCARE2X

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a Suchen action to modules/drg/mycare2x_proc_search.php; or (7) name_last or (8) pid parameter to modules/patient/mycare_pid.php.

Affected products

  • Hccgmbh MYCARE2X: affected versions not specified

Published 2012-08-13. Last modified 2026-06-16.