CVE-2018-25113 describes an unauthenticated path traversal vulnerability in Dicoogle PACS Web Server version 2.5.0 and earlier. This high-severity vulnerability (CVSS 8.7) allows remote attackers to read arbitrary files on the underlying system by sending a crafted request to the /exportFile endpoint, potentially revealing sensitive information. While not listed in CISA KEV, exploit modules are available in Metasploit, and community discussion is notably high, indicating significant interest in this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dicoogle Project | PACS Web Server | 2.5.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.