Description
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.
Problem types
CWE-1236 Improper Neutralization of Formula Elements in a CSV File
Product status
RC202503 before RC202503 2025-03-14
RC202409 before RC202409 2025-03-14
RC202403 before RC202403 2025-03-14
RC202309 before RC202309 2025-03-14
RC202303 before RC202303 2025-03-14
RC202503 2025-03-14
RC202409 2025-03-14
RC202403 2025-03-14
RC202309 2025-03-14
RC202303 2025-03-14
Credits
George Thompson, Sandia National Laboratories
Trevor LaPay, Sandia National Laboratories
Fernando Martinez, Sandia National Laboratories
Gary Huang, Sandia National Laboratories
References
raw.githubusercontent.com/...IT/white/2025/va-25-272-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35033 (url)