CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-09-02T10:00:00
Updated: 2024-08-06T11:48:48.475Z
Reserved: 2014-08-25T00:00:00
Link: CVE-2014-5452
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-09-02T10:55:04.667
Modified: 2024-11-21T02:12:05.040
Link: CVE-2014-5452
Redhat
No data.