A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser.
History

Tue, 17 Jun 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-01-23T19:20:02.324Z

Updated: 2025-06-17T21:19:26.897Z

Reserved: 2024-01-22T16:41:11.753Z

Link: CVE-2023-7238

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.227Z

cve-icon NVD

Status : Modified

Published: 2024-01-23T20:15:45.413

Modified: 2024-11-21T08:45:35.027

Link: CVE-2023-7238

cve-icon Redhat

No data.