Authentication Bypass Vulnerability in Sante PACS Server by Sante
CVE-2022-2272
9.8CRITICAL
What is CVE-2022-2272?
This vulnerability in Sante PACS Server 3.0.4 allows remote attackers to bypass authentication by exploiting a flaw in the login endpoint's username processing. The system fails to properly validate user-supplied strings before utilizing them in SQL queries, enabling unauthorized access. Consequently, attackers can execute malicious SQL commands without needing authentication, posing a significant risk to data security and integrity.
Affected Version(s)
PACS Server 3.0.4