PT-2026-3614 · Unknown · Meddream Pacs Premium

Marcin Icewall

·

Publicado

2026-01-20

·

Atualizado

2026-01-20

·

CVE-2025-58090

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MedDream PACS Premium version 7.3.6.870
Description The software contains multiple reflected cross-site scripting (xss) issues within the config.php functionality. An attacker can leverage crafted malicious URLs to execute arbitrary javascript code. The uploaddir parameter is susceptible to exploitation via specially crafted URLs.
Recommendations Apply updates to address the identified issues in the config.php functionality. As a temporary workaround, consider restricting access to the config.php functionality until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-58090

Produtos afetados

Meddream Pacs Premium