CVE Details
Basic Information
| Title | CVE-2025-32731 |
|---|---|
| Type | cve |
| Published | 2025-07-28T13:36:18.137Z |
| Modified | 2025-07-28T13:36:18.137Z |
Product Information
| Vendor | MedDream |
|---|---|
| Product | MedDream PACS Premium |
| Version | 7.3.5.860 |
CVSS Information
| Base Score | 6.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
AI Analysis
| AI Description | A reflected cross-site scripting (XSS) vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript via a crafted URL, potentially affecting the web interface. |
|---|---|
| AI Severity | Medium |
| AI Vendor | MedDream |
| AI Product | MedDream PACS Premium |
| AI Version | 7.3.5.860 |
Affected Products
- MedDream MedDream PACS Premium 7.3.5.860
Additional Information
| CWE List | CWE-79 |
|---|---|
| Source | talos |
Description
A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality of meddream MedDream PACS Premium 7.3.5.860. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.