Filtered by vendor Medical Informatics Engineering
Subscriptions
Total
5 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-35034 | 1 Medical Informatics Engineering | 1 Enterprise Health | 2025-09-30 | 4.3 Medium |
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. | ||||
CVE-2025-35033 | 1 Medical Informatics Engineering | 1 Enterprise Health | 2025-09-30 | 4.1 Medium |
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. | ||||
CVE-2025-35030 | 1 Medical Informatics Engineering | 1 Enterprise Health | 2025-09-30 | 8.1 High |
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. | ||||
CVE-2025-35032 | 1 Medical Informatics Engineering | 1 Enterprise Health | 2025-09-30 | 3.4 Low |
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. | ||||
CVE-2025-35031 | 1 Medical Informatics Engineering | 1 Enterprise Health | 2025-09-30 | 3.3 Low |
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. |
Page 1 of 1.