PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gist.github.com/leommxj/0a32afeeaac960682c5b7c9ca8ed070d | third party advisory exploit |
https://pacsone.net/download.htm | product vendor advisory |