Reflected Cross-Site Scripting in MedDream PACS by MedDream
CVE-2025-32731

6.1MEDIUM

Key Information:

Vendor

Meddream

Vendor
CVE Published:
28 July 2025

What is CVE-2025-32731?

A reflected cross-site scripting vulnerability has been identified in the radiationDoseReport.php component of MedDream PACS Premium 7.3.5.860. This vulnerability enables an attacker to execute arbitrary JavaScript code by crafting a malicious URL. When the victim interacts with this specially designed link, it can lead to unauthorized actions, including data theft or session hijacking, compromising the application's overall security and integrity.

Affected Version(s)

MedDream PACS Premium 7.3.5.860

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Marcin 'Icewall' Noga of Cisco Talos.
.
CVE-2025-32731 : Reflected Cross-Site Scripting in MedDream PACS by MedDream