Description
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
RC202503 before RC202503 2025-04-08
RC202409 before RC202409 2025-04-08
RC202403 before RC202403 2025-04-08
RC202309 before RC202309 2025-04-08
RC202503 2025-04-08
RC202409 2025-04-08
RC202403 2025-04-08
RC202309 2025-04-08
Credits
George Thompson, Sandia National Laboratories
Trevor LaPay, Sandia National Laboratories
Fernando Martinez, Sandia National Laboratories
Gary Huang, Sandia National Laboratories
References
raw.githubusercontent.com/...IT/white/2025/va-25-272-01.json (url)
www.cve.org/CVERecord?id=CVE-2025-35034 (url)