In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead to unauthorized access to patient data via a read-only web application.
2020-09-11T13:15:11.237
2024-11-21T05:06:57.580
Modified
CVSSv3.1: 3.5 (LOW)
AV:A/AC:L/Au:S/C:P/I:N/A:N
5.1
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | philips | patient_information_center_ix | b.02 | Yes |
Application | philips | patient_information_center_ix | c.02 | Yes |
Application | philips | patient_information_center_ix | c.03 | Yes |