Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 29 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meddream pacs Server
|
|
| CPEs | cpe:2.3:a:meddream:pacs_server:7.3.6.870:*:*:*:premium:*:*:* | |
| Vendors & Products |
Meddream pacs Server
|
Wed, 21 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meddream
Meddream pacs Premium |
|
| Vendors & Products |
Meddream
Meddream pacs Premium |
Tue, 20 Jan 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (xss) vulnerability exists in the fetchPriorStudies functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2026-01-21T16:01:41.918Z
Reserved: 2025-08-22T15:59:57.209Z
Link: CVE-2025-46270
Updated: 2026-01-20T17:08:46.306Z
Status : Analyzed
Published: 2026-01-20T15:16:25.447
Modified: 2026-01-29T15:23:32.253
Link: CVE-2025-46270
No data.
OpenCVE Enrichment
Updated: 2026-01-21T11:19:11Z