216.73.217.22

CVE-2020-37009

· Published 29/01/2026 15:16 · Modified 29/01/2026 17:16

Labels: CVE-2020-37009 2026-01-29CVE-2020-37009CWE-434[email protected]

Essential information

Published
29/01/2026 15:16
Modified
29/01/2026 17:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system commands with elevated privileges.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
meddream / meddream pacs server cpe:2.3:a:meddream:meddream_pacs_server:6.8.3.751:*:*:*:*:*:*:*

References