E-Health Issues (3/3) - Severe Vulnerabilities in VITU
Brief
During the last year (2025), we conducted a variety of penetration tests on E-Health applications. Shockingly, they all had severe vulnerabilities. This is particularly concerning given the highly sensitive information stored and processed by these applications. This is the final entry in a series of three blog posts in which we will disclose some of the vulnerabilities we identified.
Intro
One of our clients wanted to begin using the web application VITU (Virtuelles Tumorboard) – a process-oriented information and communication platform for the health sector – in production. However, they wanted to assess its security before doing so. Hence, we conducted a web application penetration test.
The results revealed multiple severe vulnerabilities, such as almost no authorization checks and multiple instances of stored cross-site scripting.
