CVE-2025-27954: Philips Clinical Collaboration Platform

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.

Affected products

  • Philips Clinical Collaboration Platform: version 12.2.1.5 only

Published 2025-06-02. Last modified 2026-06-17.