PT-2026-3617 · Unknown · Meddream Pacs Premium

Marcin Icewall

·

Published

2026-01-20

·

Updated

2026-01-21

·

CVE-2025-58093

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MedDream PACS Premium version 7.3.6.870
Description The software contains multiple reflected cross-site scripting (xss) issues within the config.php functionality. A crafted URL can trigger these issues, potentially leading to arbitrary javascript code execution. The phpdir parameter is involved in these vulnerabilities. An attacker can provide a malicious URL to exploit the issue.
Recommendations Apply updates to address the vulnerabilities in the config.php functionality. Sanitize user input for the phpdir parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-58093

Affected Products

Meddream Pacs Premium