Skip to content
搜索以了解InterSystems产品和解决方案,职业机会等。

Advisory: Cross-site Scripting Issue in the Clinical Viewer

March 1, 2022 – Advisory: Cross-site Scripting Issue in the Clinical Viewer

InterSystems has corrected a defect which could allow Cross-site scripting (XSS). A crafted payload within certain URI Parameters or HTTP POST Body can lead to arbitrary JavaScript execution in the Clinical Viewer in Health Share Information Exchange 2018.1 and Unified Care Record 2019.1.

The correction for this defect is identified as HSCV-8103/HSCV-8550. It is available via ad hoc change file or full kit distribution from the Worldwide Response Center (WRC). All affected customers are encouraged to request and apply the correction. The correction is included in version 2019.2 and all later product releases.

RELATED TOPICS

最新警报和通知

Mar 24, 2026
受影响的产品和版本 风险类别和评分 明确要求 DP-448888 产品:
Mar 24, 2026
受影响的产品和版本 风险类别和评分 明确要求 DP-449126 InterSystems IRIS® 数据平台
Mar 09, 2026
此问题影响 2025.2 之前的以下所有产品版本: