CVE-2023-7238: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Orthanc Osimis DICOM Web Viewer
A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7238?
CVE-2023-7238 is considered a medium severity vulnerability due to its potential for exploitation through cross-site scripting (XSS).
How do I fix CVE-2023-7238?
To mitigate CVE-2023-7238, update the Osimis WebViewer to the latest version that contains security patches addressing this vulnerability.
What types of attacks can be executed using CVE-2023-7238?
CVE-2023-7238 can be exploited to execute arbitrary JavaScript code in the context of the victim's browser.
Which versions of Osimis WebViewer are affected by CVE-2023-7238?
CVE-2023-7238 specifically affects Osimis WebViewer version 1.4.2.0-9d9eff4.
Is user interaction required to exploit CVE-2023-7238?
Yes, user interaction is necessary as the payload is triggered when a user views the infected DICOM study.