OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
CVE-2026-25860
Key Information:
- Vendor
Frankverbeke
- Status
- Vendor
- CVE Published:
- 9 June 2026
Badges
What is CVE-2026-25860?
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in popup.jsp and archiving/uploadfiles_jsp.java when processed through the Upload DICOM images feature.
Affected Version(s)
OpenClinic GA 0 <= 5.351.19
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
