CVE-2019-12741
MEDIUMHAPI FHIR < 3.8.0 - Cross-Site Scripting via Testpage Overlay HTTP Parameters
Title source: llmDescription
XSS exists in the HAPI FHIR testpage overlay module of the HAPI FHIR library before 3.8.0. The attack involves unsanitized HTTP parameters being output in a form page, allowing attackers to leak cookies and other sensitive information from ca/uhn/fhir/to/BaseController.java via a specially crafted URL. (This module is not generally used in production systems so the attack surface is expected to be low, but affected systems are recommended to upgrade immediately.)
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/jamesagnew/hapi-fhir/issues/1335
Patch, Third Party Advisory x_refsource_misc
https://github.com/jamesagnew/hapi-fhir/commit/8f41159eb147eeb964cad68b28eff97acac6ea9a
Third Party Advisory x_refsource_misc
https://github.com/jamesagnew/hapi-fhir/releases/tag/v3.8.0
Scores
CVSS v3
6.1
EPSS
0.0127
EPSS Percentile
66.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
ca.uhn.hapi.fhir/hapi-fhir-base
0 - 3.8.0Maven
fhir/hapi_fhir
< 3.8.0
Published
Jun 05, 2019
Tracked Since
Feb 18, 2026