← Back

CVE-2025-35032

nvd nist
Published: Sep 29, 2025Modified: Jan 2, 2026

JSON object

Loading...
6.2
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 9119a7d8-5eab-497f-8521-727c672e3725 (Secondary)

Description

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.

Affected (5)

1 product
Enterprise Health
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mieweb
Version rc202303
Version rc202309
Version rc202403
Version rc202409
Version rc202503

References (2)

Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory

Timeline

No history available yet.