Medical Informatics Engineering Enterprise Health vulnerabilities
6 known vulnerabilities affecting medical_informatics_engineering/enterprise_health.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2025-35032P2CRITICALCVSS 9.9fixed in 2025-04-082025-09-29
CVE-2025-35032 [CRITICAL] CWE-434 CVE-2025-35032: Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary fil
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
nvd
CVE-2025-35030P3HIGHCVSS 8.8≥ RC202503, < RC202503 2025-04-08≥ RC202409, < RC202409 2025-04-08+3 more2025-09-29
CVE-2025-35030 [HIGH] CWE-352 CVE-2025-35030: Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability tha
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08.
nvd
CVE-2025-35034P4MEDIUMCVSS 6.1≥ RC202503, < RC202503 2025-04-08≥ RC202409, < RC202409 2025-04-08+2 more2025-09-29
CVE-2025-35034 [MEDIUM] CWE-79 CVE-2025-35034: Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
nvd
CVE-2025-35029P4MEDIUMCVSS 5.4≥ RC202503, < RC202503 2025-04-08≥ RC202409, < RC202409 2025-04-08+2 more2025-11-20
CVE-2025-35029 [MEDIUM] CWE-79 CVE-2025-35029: Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability th
Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.
nvd
CVE-2025-35031P4MEDIUMCVSS 5.5≥ RC202503, < RC202503 2025-04-08≥ RC202409, < RC202409 2025-04-08+1 more2025-09-29
CVE-2025-35031 [MEDIUM] CWE-1295 CVE-2025-35031: Medical Informatics Engineering Enterprise Health includes the user's current session token in debug
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
nvd
CVE-2025-35033P4MEDIUMCVSS 4.3≥ RC202503, < RC202503 2025-03-14≥ RC202409, < RC202409 2025-03-14+3 more2025-09-29
CVE-2025-35033 [MEDIUM] CWE-1236 CVE-2025-35033: Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a re
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.
nvd