PT-2023-16661 · Unknown · Meddatapacs

Published

2023-03-06

·

Updated

2024-02-01

·

CVE-2023-0979

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MedDataPACS versions prior to 2023-03-03
Description The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows for SQL Injection attacks.
Recommendations For MedDataPACS versions prior to 2023-03-03, update to a version released after 2023-03-03 to resolve the issue. As a temporary workaround, consider restricting access to sensitive database queries to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-0979

Affected Products

Meddatapacs