CVE-2025-35034
Medical Informatics Engineering Enterprise Health reflected cross site scripting via portlet_user_id
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Medical Informatics Engineering · Enterprise Health¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →