CVE
- Id
- 71158
- CVE No.
- CVE-2014-3862
- Status
- Candidate
- Description
- CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.
- Phase
- Assigned (20140525)
- Votes
- None (candidate not yet proposed)
- Comments