Vulnerability Description
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/45337
- https://www.novarad.net
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5488.php
- https://www.exploit-db.com/exploits/45337
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5488.php
FAQ
What is CVE-2018-25142?
CVE-2018-25142 is a vulnerability with a CVSS score of 9.8 (CRITICAL). NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files w...
How severe is CVE-2018-25142?
CVE-2018-25142 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-25142?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.