Description
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
RC202503 before RC202503 2025-04-08
RC202409 before RC202409 2025-04-08
RC202403 before RC202403 2025-04-08
RC202309 before RC202309 2025-04-08
RC202303 before RC202303 2025-04-08
RC202503 2025-04-08
RC202409 2025-04-08
RC202403 2025-04-08
RC202309 2025-04-08
RC202303 2025-04-08
Credits
George Thompson, Sandia National Laboratories
Trevor LaPay, Sandia National Laboratories
Fernando Martinez, Sandia National Laboratories
Gary Huang, Sandia National Laboratories
References
raw.githubusercontent.com/...IT/white/2025/va-25-272-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35030 (url)