Description
Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Merge
Merge merge Pacs |
|
| Vendors & Products |
Merge
Merge merge Pacs |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system. | |
| Title | Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-29T19:24:32.328Z
Reserved: 2026-04-29T11:59:44.886Z
Link: CVE-2018-25298
No data.
Status : Received
Published: 2026-04-29T20:16:23.970
Modified: 2026-04-29T20:16:23.970
Link: CVE-2018-25298
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:20:51Z
Weaknesses