Vulnerability Description
A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orthanc-Server | Osimis Web Viewer | 1.4.2.0-9d9eff4 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-023-01Third Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-023-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-7238?
CVE-2023-7238 is a vulnerability with a CVSS score of 7.1 (HIGH). A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be ab...
How severe is CVE-2023-7238?
CVE-2023-7238 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-7238?
Check the references section above for vendor advisories and patch information. Affected products include: Orthanc-Server Osimis Web Viewer.