← Back

CVE-2025-35033

nvd nist
Published: Sep 29, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 9119a7d8-5eab-497f-8521-727c672e3725 (Secondary)

Description

Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.

Affected (5)

1 product
Enterprise Health
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Mieweb
Version rc202303
Version rc202309
Version rc202403
Version rc202409
Version rc202503

References (2)

Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party Advisory

Timeline

No history available yet.