PT-2026-3617 · Unknown · Meddream Pacs Premium

Marcin Icewall

·

Publicado

2026-01-20

·

Atualizado

2026-01-21

·

CVE-2025-58093

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MedDream PACS Premium version 7.3.6.870
Description The software contains multiple reflected cross-site scripting (xss) issues within the config.php functionality. A crafted URL can trigger these issues, potentially leading to arbitrary javascript code execution. The phpdir parameter is involved in these vulnerabilities. An attacker can provide a malicious URL to exploit the issue.
Recommendations Apply updates to address the vulnerabilities in the config.php functionality. Sanitize user input for the phpdir parameter to prevent the injection of malicious scripts.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-58093

Produtos afetados

Meddream Pacs Premium