Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ghwc-hrr9-vj2w

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 9.8

Описание

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

EPSS

Процентиль: 15%
0.00048
Низкий

7.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.

EPSS

Процентиль: 15%
0.00048
Низкий

7.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-611