Stored Cross-Site Scripting Vulnerability in Sante PACS Server
CVE-2025-54759

5.1MEDIUM

Key Information:

Vendor

Santesoft

Vendor
CVE Published:
18 August 2025

What is CVE-2025-54759?

The Sante PACS Server is vulnerable to stored cross-site scripting, which allows attackers to inject malicious HTML code into the system. This vulnerability can redirect users to malicious websites, enabling cookie theft and potential unauthorized access to sensitive information. It is crucial for users to stay informed and implement necessary security measures to protect against such exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Sante PACS Server 0 < 4.2.3

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chizuru Toyama of TXOne Networks reported these vulnerabilities to CISA.
.