Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 10 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frankverbeke
Frankverbeke openclinic Ga |
|
| Vendors & Products |
Frankverbeke
Frankverbeke openclinic Ga |
Tue, 09 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in popup.jsp and archiving/uploadfiles_jsp.java when processed through the Upload DICOM images feature. | |
| Title | OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-10T13:21:01.796Z
Reserved: 2026-02-06T19:12:03.463Z
Link: CVE-2026-25860
Updated: 2026-06-10T13:20:48.872Z
Status : Deferred
Published: 2026-06-09T22:16:22.303
Modified: 2026-06-10T19:41:25.327
Link: CVE-2026-25860
No data.
OpenCVE Enrichment
Updated: 2026-06-10T11:21:58Z