Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input
before it is placed in output used as a webpage that is served to other
users.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-6661 Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
Fixes

Solution

Philips released the Clinical Collaboration Platform patch 12.2.1.5 in June 2020 for web portals to remediate CVE-2020-14525. Philips Clinical Collaboration Platform Version 12.2.5 was released in May 2020 to remediate CVE-2020-14525. Users with questions regarding their specific Philips Clinical Collaboration Platform installations and new release eligibility should contact Philips service support, or regional service support https://www.usa.philips.com/healthcare/solutions/customer-service-solutions , or call 1-877-328-2808, option 4. The Philips advisory and the latest security information for Philips products are available at the Philips product security website https://www.philips.com/productsecurity .


Workaround

No workaround given by the vendor.

History

Wed, 04 Jun 2025 21:30:00 +0000

Type Values Removed Values Added
Description Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users. Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
Title Philips Clinical Collaboration Platform Improper Neutralization of Script in Attributes in a Web Page
References

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-06-04T21:12:52.643Z

Reserved: 2020-06-19T00:00:00

Link: CVE-2020-14525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-09-18T18:15:16.690

Modified: 2025-06-04T22:15:23.333

Link: CVE-2020-14525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.