PT-2025-31104 · Meddream · Meddream Pacs Premium

·

CVE-2025-32731

·

Published

2025-07-28

·

Updated

2025-07-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions meddream MedDream PACS Premium version 7.3.5.860
Description A reflected cross-site scripting (xss) vulnerability exists in the radiationDoseReport.php functionality. A specially crafted URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.
Recommendations Apply updates to address the vulnerability in the radiationDoseReport.php functionality. As a temporary workaround, sanitize all user inputs and validate URLs to prevent the injection of malicious scripts.

Exploit

Fix

DoS

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32731

Affected Products

Meddream Pacs Premium