Aggregates CVE and security vulnerability intelligence across all mieweb-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk cross-site scripting and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-35029 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 4.8 | 0.17% | 2025-11-20 | 2025-12-31 |
| CVE-2025-35034 | Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 5.1 | 0.24% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35033 | Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. | 9119a7d8-5eab-497f-8521-727c672e3725 | 6.3 | 0.22% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35032 | Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 6.2 | 0.23% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35031 | Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 4.6 | 0.13% | 2025-09-29 | 2026-01-02 |
| CVE-2025-35030 | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. | 9119a7d8-5eab-497f-8521-727c672e3725 | 8.6 | 0.18% | 2025-09-29 | 2026-01-02 |