CVE-2018-25298
MEDIUMMerge PACS 7.0 Cross-Site Request Forgery via merge-viewer
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25298. PoCs published by Safak Aslan.
AI-analyzed exploit summary This is a functional CSRF exploit for Merge PACS 7.0 that demonstrates how an attacker can trick a victim into submitting a login request via a crafted HTML form. The PoC includes both the HTML form and the raw HTTP POST request data.
Description
Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system.
Exploits (1)
This is a functional CSRF exploit for Merge PACS 7.0 that demonstrates how an attacker can trick a victim into submitting a login request via a crafted HTML form. The PoC includes both the HTML form and the raw HTTP POST request data.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N