Password Vulnerability in Sante PACS Server by Sante Health
CVE-2025-2265
7.8HIGH
What is CVE-2025-2265?
A vulnerability exists in Sante PACS Server where user passwords are zero-padded to 0x2000 bytes and SHA1-hashed. The hash is subsequently base64-encoded and stored in the USER table within the SQLite database HTTP.db. However, if the hash result contains a zero byte, there is a risk that the encoded hash will be truncated, leading to potential exposure of user credentials.
Affected Version(s)
Sante PACS Server 4.1.0
Sante PACS Server 4.2.0