vendor:
Merge PACS
by:
Safak Aslan
7.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: Merge PACS
Affected Version From: Merge PACS 7.0
Affected Version To: Merge PACS 7.0
Patch Exists: NO
Related CWE: N/A
CPE: a:merge_healthcare:merge_pacs:7.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Merge PACS 7.0 – Cross-Site Request Forgery
Merge PACS 7.0 is vulnerable to Cross-Site Request Forgery. An attacker can craft a malicious HTML page that contains a form with hidden parameters and submit it to the target server. This can be used to perform malicious actions on behalf of the user.
Mitigation:
Implementing a security policy that requires user authentication for all requests and validating all input parameters.