Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.

Project Subscriptions

Vendors Products
Medical Informatics Engineering Subscribe
Enterprise Health Subscribe
Enterprise Health Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 31 Dec 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mieweb
Mieweb enterprise Health
CPEs cpe:2.3:a:mieweb:enterprise_health:rc202309:-:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202403:-:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202409:-:*:*:*:*:*:*
cpe:2.3:a:mieweb:enterprise_health:rc202503:-:*:*:*:*:*:*
Vendors & Products Mieweb
Mieweb enterprise Health

Tue, 02 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Medical Informatics Engineering
Medical Informatics Engineering enterprise Health
Vendors & Products Medical Informatics Engineering
Medical Informatics Engineering enterprise Health

Thu, 20 Nov 2025 19:45:00 +0000

Type Values Removed Values Added
Description Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14.
Title Medical Informatics Engineering Enterprise Health stored cross site scripting via Demographic Information page
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2025-12-02T14:54:03.350Z

Reserved: 2025-04-15T20:56:24.403Z

Link: CVE-2025-35029

cve-icon Vulnrichment

Updated: 2025-12-02T14:53:51.667Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-20T20:16:22.187

Modified: 2025-12-31T13:51:52.017

Link: CVE-2025-35029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-24T09:09:57Z

Weaknesses