Description
Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
RC202503 (custom) before RC202503 2025-04-08
RC202409 (custom) before RC202409 2025-04-08
RC202403 (custom) before RC202403 2025-04-08
RC202309 (custom) before RC202309 2025-04-08
RC202503 2025-04-08
RC202409 2025-04-08
RC202403 2025-04-08
RC202309 2025-04-08
Credits
George Thompson, Sandia National Laboratories
Trevor LaPay, Sandia National Laboratories
Fernando Martinez, Sandia National Laboratories
Gary Huang, Sandia National Laboratories
References
raw.githubusercontent.com/...IT/white/2025/va-25-272-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35029 (url)