CVE-2025-35032CRITICAL 9.9EPSS p13.7%
CVE-2025-35032CVE-2025-35032
Description
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
Scoring
| CVSS 3.1 | 9.9 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 13.7% · 2026-06-18T12:00:27Z |
| Published | 2025-09-29 |
| Last modified | 2026-01-02 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unrestricted Upload of File with Dangerous Typecwe-434 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.