๐Ÿ” CVE Alert

CVE-2026-25860

MEDIUM 6.1

OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in popup.jsp and archiving/uploadfiles_jsp.java when processed through the Upload DICOM images feature.

CWE CWE-79
Vendor frankverbeke
Product openclinic ga
Published Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for frankverbeke openclinic ga

Be the first to know when new medium vulnerabilities affecting frankverbeke openclinic ga are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

frankverbeke / OpenClinic GA
0 โ‰ค 5.351.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
partywave.site: https://www.partywave.site/show/research/cve-2026-25860-openclinic-ga-xss-to-rce github.com: https://github.com/partywavesec/CVE-2026-25860 vulncheck.com: https://www.vulncheck.com/advisories/openclinic-ga-reflected-xss-via-dicom-image-upload-handler

Credits

partywave VulnCheck