MedDream PACS Server Premium
cpe:2.3:a:softneta:meddream_pacs:*:*:*:*:*:*:*
- <= 6.7.1.1
A SQL injection vulnerability has been identified in MedDream PACS Server Premium version 6.7.1.1. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Exploitation involves sending crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field, enabling attackers to extract sensitive information from the backend MySQL database.
Exploitation of this vulnerability allows for arbitrary SQL execution, which could lead to unauthorized data access or manipulation within the database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.