EIP-2026-119431

PRE-CVE

SonicDICOM PACS 2.3.2 - Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119431. PoCs published by LiquidWorm.

AI-analyzed exploit summary The exploit demonstrates multiple stored XSS vulnerabilities in SonicDICOM PACS 2.3.2 via unsanitized POST parameters in the settings, sendsettings, and providers APIs. The PoC includes HTML forms that submit malicious scripts, which are stored and executed in the context of the affected site.

Description

SonicDICOM PACS 2.3.2 - Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · htmlwebappswindows
https://www.exploit-db.com/exploits/41309

The exploit demonstrates multiple stored XSS vulnerabilities in SonicDICOM PACS 2.3.2 via unsanitized POST parameters in the settings, sendsettings, and providers APIs. The PoC includes HTML forms that submit malicious scripts, which are stored and executed in the context of the affected site.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SonicDICOM PACS 2.3.2 and 2.3.1
No auth needed
Prerequisites: Access to the target application's API endpoints
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026