Aller au contenu

Fiche vulnérabilité

CVE-2025-35030 : faille élevée mieweb enterprise health (CVSS 8.8)

Description

Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
29 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • mieweb enterprise health

Références

Rechercher une autre vulnérabilité dans la base CVE