Vulnerability Details CVE-2025-35033
Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 10.1%
CVSS Severity
CVSS v3 Score 4.1
Products affected by CVE-2025-35033
-
cpe:2.3:a:mieweb:enterprise_health:rc202303
-
cpe:2.3:a:mieweb:enterprise_health:rc202309
-
cpe:2.3:a:mieweb:enterprise_health:rc202403
-
cpe:2.3:a:mieweb:enterprise_health:rc202409
-
cpe:2.3:a:mieweb:enterprise_health:rc202503