Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://orthanc.uclouvain.be/hg/orthanc/rev/505416b269a0 | patch |
https://orthanc.uclouvain.be/hg/orthanc/file/Orthanc-1.12.2/NEWS | vendor advisory |