First published: Fri Sep 18 2020(Updated: )
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Philips Clinical Collaboration Platform | <=12.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14525 is a vulnerability found in Philips Clinical Collaboration Platform versions 12.2.1 and prior.
CVE-2020-14525 has a severity rating of low.
CVE-2020-14525 allows user-controllable input to be placed in output used as a webpage served to other users, making it vulnerable to potential attacks.
To fix CVE-2020-14525, it is recommended to update Philips Clinical Collaboration Platform to version 12.2.2 or later.
More information about CVE-2020-14525 can be found at https://us-cert.cisa.gov/ics/advisories/icsma-20-261-01.