VulnSea

enterprise_health vulnerabilities

CVEs whose affected-version data names the enterprise_health package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2025-35034Medium· 4.3
1y ago

Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter

Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the …

▾ Sunlitmieweb · enterprise_healthEPSS 0.26%via NVD
CVE-2025-35033Medium· 4.1
1y ago

Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files

Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.

▾ Sunlitmieweb · enterprise_healthEPSS 0.24%via NVD
CVE-2025-35032Low· 3.4
1y ago

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.

▾ Sunlitmieweb · enterprise_healthEPSS 0.25%via NVD
CVE-2025-35031Low· 3.3
1y ago

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This…

▾ Sunlitmieweb · enterprise_healthEPSS 0.14%via NVD
CVE-2025-35030High· 8.1
1y ago

Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that admi…

Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that admi…

▾ Twilightmieweb · enterprise_healthEPSS 0.20%via NVD
enterprise_health vulnerabilities (CVEs) · VulnSea