Loading
Generated remediation guidance and an executive summary. No account required.
A XSS payload can be uploaded as a DICOM study and when a user tries to view the infected study inside the Osimis WebViewer the XSS vulnerability gets triggered. If exploited, the attacker will be able to execute arbitrary JavaScript code inside the victim's browser.
Use CWE-79, Orthanc-Server vendor hub and Osimis Web Viewer product page to widen CVE-2023-7238 into its surrounding weakness, vendor, and product context.