CVE-2025-35031
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-1295
- Published
- 2025-09-29
- Last modified
- 2026-03-12
Affected products
- Medical Informatics Engineering Enterprise Health
- Medical Informatics Engineering Enterprise Health
- Medical Informatics Engineering Enterprise Health
- Medical Informatics Engineering Enterprise Health
- Medical Informatics Engineering Enterprise Health
- Medical Informatics Engineering Enterprise Health
Weakness type
Related vulnerabilities
- CVE-2026-28811 — Apache JSPWiki: Error Handling - Reveals Error Details
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-59109 — UART Leaking Sensitive Data in dormakaba registration unit 9002
- CVE-2025-46775 — A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0...
- CVE-2025-42604 — Detailed Error Response Vulnerability in Meon KYC solutions
- CVE-2025-2469 — Debug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-31001 — WordPress GTM Kit plugin <= 2.4.0 - Sensitive Data Exposure vulnerability
- CVE-2025-2877 — Event-driven-ansible: exposure inventory passwords in plain text when starting a rulebook activation with verbosity set to debug in eda