PT-2026-3616 · Unknown · Meddream Pacs Premium

Marcin Icewall

·

Published

2026-01-20

·

Updated

2026-01-20

·

CVE-2025-58092

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MedDream PACS Premium version 7.3.6.870
Description The software contains multiple reflected cross-site scripting (xss) issues within the config.php functionality. A crafted URL can trigger these issues, potentially leading to arbitrary javascript code execution. The phpexe parameter is involved in the exploitation of these issues.
Recommendations Apply updates to address the identified issues in the config.php functionality. As a temporary workaround, consider restricting access to the config.php functionality or carefully validating all input to the phpexe parameter.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-58092

Affected Products

Meddream Pacs Premium