CVE-2025-35030
HIGHMieweb Enterprise Health - CSRF
Title source: ruleDescription
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08.
Scores
CVSS v3
8.1
EPSS
0.0002
EPSS Percentile
5.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Classification
CWE
CWE-352
Status
published
Affected Products (5)
mieweb/enterprise_health
mieweb/enterprise_health
mieweb/enterprise_health
mieweb/enterprise_health
mieweb/enterprise_health
Timeline
Published
Sep 29, 2025
Tracked Since
Feb 18, 2026