Intesync develops a small portfolio of web-based medical and administrative software products, notably SolisMed and MiniWeb, that handle sensitive healthcare data and are deployed in clinical and organizational settings. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, concentrating in web-application weakness classes including cross-site scripting, SQL injection, path traversal, cross-site request forgery, and UI-layer framing issues that are characteristic of input-handling and access-control gaps in healthcare-facing applications. Defenders should treat updates for this vendor's products as high-priority given the combination of serious severity outcomes and public exploit availability; live exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Intesync over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16246CRITICAL Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution. | Dec 12, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-15931CRITICAL Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246. | Dec 12, 2019 | 9.8 | 29 | NO | NO |
CVE-2009-4551HIGH SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to | Jan 4, 2010 | 7.5 | 28 | NO | YES |
CVE-2009-3419HIGH SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter. | Sep 25, 2009 | 7.5 | 28 | NO | YES |
CVE-2019-15936CRITICAL Intesync Solismed 3.3sp allows Insecure File Upload. | Dec 12, 2019 | 9.8 | 27 | NO | NO |
CVE-2019-15933CRITICAL Intesync Solismed 3.3sp has SQL Injection. | Dec 12, 2019 | 9.8 | 27 | NO | NO |
CVE-2019-15932CRITICAL Intesync Solismed 3.3sp has Incorrect Access Control. | Dec 12, 2019 | 9.8 | 27 | NO | NO |
CVE-2019-15934HIGH Intesync Solismed 3.3sp has CSRF. | Dec 12, 2019 | 8.8 | 25 | NO | NO |
CVE-2009-4552MEDIUM Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | Jan 4, 2010 | 4.3 | 21 | NO | YES |
CVE-2009-3420MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) b | Sep 25, 2009 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Intesync.
Media articles that mention a CVE ID that affects a product developed by Intesync — matched by CVE ID, not by vendor name.