CVE-2023-33255
Summary
| CVE | CVE-2023-33255 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-26 20:15:00 UTC |
| Updated | 2023-06-09 19:15:00 UTC |
| Description | An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya web application. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Uthscsa | Papaya Viewer | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Willkommen bei SCHUTZWERK | MISC | schutzwerk.com | |
| Full Disclosure: SCHUTZWERK-SA-2022-001: Cross-Site-Scripting in Papaya Medical Viewer | FULLDISC | seclists.org | |
| www.schutzwerk.com/advisories/SCHUTZWERK-SA-2022-001.txt | MISC | www.schutzwerk.com | |
| Advisory: Cross-Site-Scripting in Papaya Medical Viewer (CVE-2023-33255) - SCHUTZWERK | MISC | www.schutzwerk.com | |
| Papaya Medical Viewer 1.0 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.