[CVE-2025-15581] Orthanc 1.12.9 User Impersonation
projectblack.io | research | CVE-2025-15581 | #appsec | #vulnerability-research | #vulnerability | #healthcare | #impersonation | #orthanc | #dicom | #cve-2025-15581
Summary
User impersonation in Orthanc DICOM server (CVE-2025-15581): its auth filter takes everything before the first colon as the username, so a crafted username impersonates others. Fixed in 1.12.10.
- Published
- Collected
Skip to content