Reflected Cross-Site Scripting in MedDream PACS Premium by MedDream
CVE-2025-58094

6.1MEDIUM

Key Information:

Vendor

Meddream

Vendor
CVE Published:
20 January 2026

What is CVE-2025-58094?

MedDream PACS Premium version 7.3.6.870 suffers from multiple reflected cross-site scripting vulnerabilities within its config.php functionality. Attackers can exploit these vulnerabilities by crafting malicious URLs that, when accessed, execute arbitrary JavaScript code in a victim's browser. Specifically, the 'worklistsrc' parameter is targeted, allowing potential disruptions and unauthorized actions. It is vital for users to implement security measures to fend off these threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MedDream PACS Premium 7.3.6.870

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Marcin 'Icewall' Noga of Cisco Talos.
.