CVE-2014-5452: XSS
CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5452?
CVE-2014-5452 is classified as a medium severity vulnerability due to its potential to enable XSS attacks.
How do I fix CVE-2014-5452?
To fix CVE-2014-5452, update your HL7 C-CDA software to a version later than 1.1 that addresses this vulnerability.
What type of attack does CVE-2014-5452 enable?
CVE-2014-5452 enables remote attackers to conduct cross-site scripting (XSS) attacks.
Which versions of HL7 C-CDA are affected by CVE-2014-5452?
CVE-2014-5452 affects all versions of HL7 C-CDA 1.1 and earlier.
What components are involved in the CVE-2014-5452 vulnerability?
The vulnerability involves the CDA.xsl stylesheet in HL7 C-CDA documents that mishandles crafted XML attributes.