CVE-2025-35034EPSS p16.0%
CVE-2025-35034CVE-2025-35034
mieweb / enterprise_health
Description
Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 0.26% probability of exploitation · percentile 16.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |