1.
projectblack.io | research | | original ↗ | #appsec | #vulnerability-research | #vulnerability | #healthcare
User impersonation in Orthanc DICOM server (CVE-2025-15581): its auth filter takes everything before the first colon as the username, so a crafted username impersonates others. Fixed in 1.12.10.
Skip to content