eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.Referenceshttps://www.exploit-db.com/exploits/39402/http://www.securityfocus.com/archive/1/537420/100/0/threadedhttp://packetstormsecurity.com/files/135533/eClinicalWorks-Population-Health-CCMR-SQL-Injection-CSRF-XSS.html