CVE-2014-3861: XSS
Published Sep 2, 2014
·Updated
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.
Affected Software
1 affected component
HL7 C-CDA<=1.1
Remediation
Event History
Sep 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3861?
CVE-2014-3861 is classified as a moderate severity vulnerability due to its potential for remote code execution through cross-site scripting.
2
How do I fix CVE-2014-3861?
To mitigate CVE-2014-3861, update to a version of HL7 C-CDA later than 1.1 that includes appropriate sanitation for user input.
3
What software is affected by CVE-2014-3861?
CVE-2014-3861 affects HL7 C-CDA version 1.1 and earlier.
4
What type of vulnerability is CVE-2014-3861?
CVE-2014-3861 is a cross-site scripting (XSS) vulnerability.
5
What impact could CVE-2014-3861 have?
Exploitation of CVE-2014-3861 could allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data and security.