Web Application Vulnerability in Philips Clinical Collaboration Platform
CVE-2020-14525

3.5LOW

Key Information:

Vendor
Philips
Vendor
CVE Published:
18 September 2020

Summary

The Philips Clinical Collaboration Platform suffers from an input validation error where user-controlled input is not properly sanitized before being rendered as a webpage. This flaw can lead to the potential exposure of sensitive user data or allow for the injection of malicious content, affecting the integrity and security of the platform. Implementing appropriate measures to ensure proper input sanitization is crucial to safeguarding the application and its users from potential threats.

Affected Version(s)

Philips Clinical Collaboration Platform Versions 12.2.1 and prior

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.