Medium severity6.1NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-33255
CVE-2023-33255
Description
An issue was discovered in Papaya Viewer 1.0.1449. User-supplied input in form of DICOM or NIFTI images can be loaded into the Papaya web application without any kind of sanitization. This allows injection of arbitrary JavaScript code into image metadata, which is executed when that metadata is displayed in the Papaya web application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:uthscsa:papaya_viewer:1.0:*:*:*:*:*:*:*
- Papaya Viewer/Papaya Viewerdescription
- Range: = 1.0.1449
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/172644/Papaya-Medical-Viewer-1.0-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2023/May/21nvdExploitMailing ListThird Party Advisory
- www.schutzwerk.com/advisories/SCHUTZWERK-SA-2022-001.txtnvdThird Party Advisory
- schutzwerk.comnvdNot Applicable
- www.schutzwerk.com/blog/schutzwerk-sa-2022-001/nvd
News mentions
0No linked articles in our index yet.