CVE-2024-22725: XSS
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Orthancto a version that resolves this vulnerability.Fixed in 1.12.2 - Configuration
Because the reflected XSS vulnerability is present in the server's error reporting, disable or reduce detailed error reporting in Orthanc (error messages/error reporting) to avoid rendering attacker-influenced content.
Orthanc server error reporting = disable or reduce detailed error reporting
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22725?
CVE-2024-22725 is classified as a medium severity vulnerability due to its potential exploitation through reflected XSS.
How do I fix CVE-2024-22725?
To fix CVE-2024-22725, upgrade Orthanc to version 1.12.2 or later.
What versions of Orthanc are affected by CVE-2024-22725?
Orthanc versions prior to 1.12.2 are affected by CVE-2024-22725.
What type of vulnerability is CVE-2024-22725?
CVE-2024-22725 is a reflected cross-site scripting (XSS) vulnerability.
What impact does CVE-2024-22725 have on users?
CVE-2024-22725 can potentially allow attackers to execute malicious scripts in the context of a user's session.