CVE-2019-6562: XSS
Published May 1, 2019
·Updated
In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Affected Software
1 affected component
Philips Tasy EMR<=3.02.1744
Event History
May 1, 2019
CVE Published
via MITRE·06:23 PM
Data Sourced
via MITRE·06:23 PM
DescriptionWeakness
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2019-6562.
2
What is the severity level of CVE-2019-6562?
The severity level of CVE-2019-6562 is medium with a CVSS score of 5.4.
3
Which software versions are affected by CVE-2019-6562?
Philips Tasy EMR Versions 3.02.1744 and prior are affected by CVE-2019-6562.
4
How does CVE-2019-6562 impact users?
CVE-2019-6562 allows attackers to inject malicious code into web pages, potentially leading to unauthorized access or data manipulation.
5
Is there a fix available for CVE-2019-6562?
It is recommended to update to a version of Philips Tasy EMR that is higher than 3.02.1744 to mitigate the vulnerability.