Security Flaws Found in NextGen Healthcare's Mirth Connect Software
CISA has issued an advisory covering multiple vulnerabilities in NextGen Healthcare Mirth Connect, a widely used data integration platform for healthcare organisations. Versions 4.7.1 and earlier are affected by flaws including an SQL injection vulnerability and an XML external entity issue, rated 8.3 out of 10 in severity.
One of the flaws allows an authenticated user to run arbitrary SQL commands through the software's Database Connector API. This could expose stored credentials for connected systems, allow attackers to write files onto affected servers, or cause a denial-of-service condition that disrupts operations. Mirth Connect is deployed worldwide within the healthcare and public health sector, making this a significant concern for clinics, medical practices, and health service providers that rely on it to exchange patient and system data.
NextGen Healthcare has recommended that users apply the available vendor fix to remediate the issue. Businesses running Mirth Connect, including smaller medical practices using third-party IT providers, should confirm with their vendor or IT support that patches have been applied.