CVE-2026-25860
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in popup.jsp and archiving/uploadfiles_jsp.java when processed through the Upload DICOM images feature.
Published:Jun 9, 2026
Last Modified:Jul 14, 2026
EPS:Jun 9, 2026
EPSS Score:0.00293
CVSS Score:6.1
Affected Products
Vendor
Product
Action
Vendor
Frankverbeke
Product
Openclinic Ga
Frankverbeke
Openclinic Ga
Vendor
Openclinic Ga Project
Product
Openclinic Ga
Openclinic Ga Project
Openclinic Ga
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
