Executive brief
Dataprom Informatics PACS-ACSS, a system used for managing medical imaging and patient data, contains a security vulnerability that allows for cross-site scripting. An attacker could use this flaw to inject malicious scripts into the web interface, potentially leading to unauthorized access to patient records or the disruption of medical workflows. This could impact the confidentiality of sensitive health information and the overall reliability of the diagnostic system.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Dataprom Informatics PACS-ACSS due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability is reachable over the network and does not require authentication or user interaction according to the provided CVSS vector (UI:N). An attacker can exploit this to execute arbitrary scripts in the context of a user's browser session, potentially leading to session hijacking or unauthorized data access. The issue is addressed in versions released on or after May 16, 2025.
Affected products
- Dataprom Informatics PACS-ACSS before 16.05.2025
Timeline
- 2025-07-23: advisory: Initial NVD publication date
- 2025-05-16: patched: Versions released after this date are reported as fixed