Record summary

CVE-2018-25298 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.

Description

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and gain unauthorized access to the PACS system.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List7.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBMerge PACS 7.0 - Cross-Site Request ForgeryExploitDB exploitby Safak AslanNot analyzed1 file
ExploitDB

PoC details

References

4