NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Title | NovaRad NovaPACS Diagnostics Viewer 8.5 XML External Entity Injection | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:25:54.871Z
Reserved: 2025-12-24T14:28:02.435Z
Link: CVE-2018-25142
Updated: 2025-12-24T20:12:17.268Z
Status : Received
Published: 2025-12-24T20:15:48.430
Modified: 2025-12-24T21:15:59.720
Link: CVE-2018-25142
No data.
OpenCVE Enrichment
No data.