OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embedding malicious payloads in DICOM file metadata fields. Attackers can craft a DICOM file with JavaScript payloads in metadata fields such as Study Description, which are reflected without sanitization in popup.jsp and archiving/uploadfiles_jsp.java when processed through the Upload DICOM images feature.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
frankverbeke · OpenClinic GApublic PoCs found — 2
cve_referencegithub.com/partywavesec/CVE-2026-25860★ 0cve_referencewww.partywave.site/show/research/cve-2026-25860-openclinic-ga-xss-to-rceunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.