PacsOne Server version 6.6.2 (prior versions are likely...
High severity
Unreviewed
Published
Nov 11, 2025
to the GitHub Advisory Database
•
Updated Nov 11, 2025
Description
Published by the National Vulnerability Database
Nov 10, 2025
Published to the GitHub Advisory Database
Nov 11, 2025
Last updated
Nov 11, 2025
PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within the web-based DICOM viewer component. Successful exploitation allows a remote unauthenticated attacker to read arbitrary files via the 'nocache.php' endpoint with a crafted 'path' parameter. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-07 UTC.
References