mieweb 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk cross-site scripting and vendor risk csrf などに関し、一部は vendor impact session compromise を招き、vendor surface software deployment and vendor surface production workloads 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2025-35029 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 4.8 | 0.17% | 2025-11-20 | 2025-12-31 |
| CVE-2025-35034 | Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 5.1 | 0.24% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35033 | Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 6.3 | 0.22% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35032 | Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 6.2 | 0.23% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35031 | Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 4.6 | 0.13% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35030 | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 8.6 | 0.18% | 2025-09-29 | 2026-01-02 |