Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 9.1
Описание
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
Связанные уязвимости
CVSS3: 9.1
nvd
3 месяца назад
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.