CVE-2025-35032
Last modified
CVE-2025-35032 is a medium-severity vulnerability rated 6.2/10 on the CVSS scale. Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mieweb | Enterprise Health | rc202303 |
| Mieweb | Enterprise Health | rc202309 |
| Mieweb | Enterprise Health | rc202403 |
| Mieweb | Enterprise Health | rc202409 |
| Mieweb | Enterprise Health | rc202503 |
References
- https://www.cve.org/CVERecord?id=CVE-2025-35032Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-35032?
How severe is CVE-2025-35032?
How do I fix CVE-2025-35032?
Are you affected by CVE-2025-35032?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
