PT-2026-3591 · Unknown · Meddream Pacs Premium

Marcin Icewall

·

Publicado

2026-01-20

·

Atualizado

2026-01-20

·

CVE-2025-36556

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MedDream PACS Premium version 7.3.6.870
Description A reflected cross-site scripting (xss) issue exists within the ldapUser functionality. A malicious URL, specifically crafted, can result in the execution of arbitrary javascript code. An attacker can trigger this by providing a crafted URL. The ldapUser functionality is susceptible to this attack.
Recommendations Apply updates to address the issue in the ldapUser functionality.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-36556

Produtos afetados

Meddream Pacs Premium