HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2018-25372 — MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability tha...

·Source: NIST NVD

Updated:

Executive Summary

MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database.

Analysis

MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database. CVSS Score: 8.2. Published: 2026-05-25T15:16:20.120.

Indicators of Compromise (2)

CVE (1)
CVE-2018-25372
Source Attribution

Originally published by NIST NVD on May 25, 2026. Verified by: NIST.

Related Threats