Reflected Cross-Site Scripting in MedDream PACS by MedDream
CVE-2025-32731
6.1MEDIUM
What is CVE-2025-32731?
A reflected cross-site scripting vulnerability has been identified in the radiationDoseReport.php component of MedDream PACS Premium 7.3.5.860. This vulnerability enables an attacker to execute arbitrary JavaScript code by crafting a malicious URL. When the victim interacts with this specially designed link, it can lead to unauthorized actions, including data theft or session hijacking, compromising the application's overall security and integrity.
Affected Version(s)
MedDream PACS Premium 7.3.5.860
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Marcin 'Icewall' Noga of Cisco Talos.