Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3pc-ww42-cwqp

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 9.1

Описание

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

EPSS

Процентиль: 48%
0.0064
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
3 месяца назад

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

EPSS

Процентиль: 48%
0.0064
Низкий

8.8 High

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22