PatchSiren

Softneta CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Softneta CVE published 2026-05-25

CVE-2018-25374

A directory traversal vulnerability in Softneta MedDream PACS Server Premium 6.7.1.1 allows unauthenticated remote attackers to read arbitrary files via path manipulation in nocache.php. The vulnerability is exploitable through encoded backslash sequences that bypass path validation, enabling access to sensitive system files including configuration and password files. The CVSS 4.0 vector indicates network [truncated]