Описание
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
EPSS
Процентиль: 48%
0.0064
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 9.1
github
3 месяца назад
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
EPSS
Процентиль: 48%
0.0064
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-22