Reflected Cross-Site Scripting in MedDream PACS Premium by MedDream
CVE-2025-58094
6.1MEDIUM
What is CVE-2025-58094?
MedDream PACS Premium version 7.3.6.870 suffers from multiple reflected cross-site scripting vulnerabilities within its config.php functionality. Attackers can exploit these vulnerabilities by crafting malicious URLs that, when accessed, execute arbitrary JavaScript code in a victim's browser. Specifically, the 'worklistsrc' parameter is targeted, allowing potential disruptions and unauthorized actions. It is vital for users to implement security measures to fend off these threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MedDream PACS Premium 7.3.6.870
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Marcin 'Icewall' Noga of Cisco Talos.
