Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-24065PUBLISHED: 2023-01-29
NOSH 4a5cfdb allows stored XSS via the create user page. For example, a first name (of a physician, assistant, or billing user) can have a JavaScript payload that is executed upon visiting the /users/2/1 page. This may allow attackers to steal Protected Health Information because the product is for ...
CVE-2023-0565PUBLISHED: 2023-01-29Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2023-0566PUBLISHED: 2023-01-29Static Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
CVE-2009-10003PUBLISHED: 2023-01-29
A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 0.7 is ...
CVE-2016-15022PUBLISHED: 2023-01-29
A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file check_system.php. The manipulation of the argument $_SERVER['SERVER_SOFTWARE'] leads to cross site scripting. The attack can be launche...
User Rank: Strategist
6/18/2015 | 2:25:48 PM
As far as scary goes...I'd say it's serious but not scary, because unlike the horror movie, we know exactly what to do about it.
Hope that no one thinks this is a call to do nothing and wait until everything is perfect. In fact, it's quite the opposite, as doing nothing about security is part of the problem today. No one should be waiting to employ best security practices: the technologies already exist today to address these serious risks. Employing them doesn't get in the way of using the Healthcare Internet of Things. Hardening the device can be as straightforward as providing for immutable device identity, a secure boot and application whitelisting. Failure to adopt security will lead to distrust of the Healthcare IoT and get in the way of its adoption. There is no reason to wait.