AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-35034.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.1CVSS 4.0 · 9119a7d8-5eab-497f-8521-727c672e3725
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSAnalyzedModified Oct 09, 2026

Disclosure summary

Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14.

Source-reported weakness categories

CWE-79

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2025-35034

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
miewebenterprise_healthrc202309
miewebenterprise_healthrc202403
miewebenterprise_healthrc202409
miewebenterprise_healthrc202503

Original records & references

PUBLISHED 2025-09-29T16:15:33-04:00
MODIFIED 2026-10-09T05:10:00-04:00
INGESTED 2026-10-10T20:50:24-04:00