A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-01-23T19:20:02.324Z

Updated: 2024-08-02T08:57:35.227Z

Reserved: 2024-01-22T16:41:11.753Z

Link: CVE-2023-7238

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2024-01-23T20:15:45.413

Modified: 2024-11-21T08:45:35.027

Link: CVE-2023-7238

cve-icon Redhat

No data.