mieweb CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

mieweb vulnerability overview

Aggregates CVE and security vulnerability intelligence across all mieweb-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-35029 Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14. 9119a7d8-5eab-497f-8521-727c672e3725 4.8 0.17% 2025-11-20 2025-12-31
CVE-2025-35034 Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. 9119a7d8-5eab-497f-8521-727c672e3725 5.1 0.24% 2025-09-29 2026-01-02
CVE-2025-35033 Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. 9119a7d8-5eab-497f-8521-727c672e3725 6.3 0.22% 2025-09-29 2026-01-02
CVE-2025-35032 Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. 9119a7d8-5eab-497f-8521-727c672e3725 6.2 0.23% 2025-09-29 2026-01-02
CVE-2025-35031 Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. 9119a7d8-5eab-497f-8521-727c672e3725 4.6 0.13% 2025-09-29 2026-01-02
CVE-2025-35030 Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. 9119a7d8-5eab-497f-8521-727c672e3725 8.6 0.18% 2025-09-29 2026-01-02
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence