S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-29164 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in PacsOne Server (PACS Server In One Box) affects v. below 7.1.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-29164
6.1
CVSS

PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by cross-site scripting (XSS).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PacsOne Server (PACS Server In One Box) is a medical image management system that enables healthcare professionals to conveniently store, retrieve, and share electronic medical images such as x-rays, MRIs, and CT scans. This powerful software solution can significantly improve the efficiency and accuracy of diagnostic imaging and reporting across various medical specialties such as radiology, cardiology, and pathology.

However, a critical security flaw has been identified in PacsOne Server below version 7.1.1, labeled as CVE-2020-29164. This cross-site scripting (XSS) vulnerability can allow an attacker to inject and execute malicious scripts in the context of a web page served by the application, potentially stealing sensitive data, causing data manipulation or system disruption, or launching further attacks on other targets.

When this vulnerability is successfully exploited, it can lead to a multitude of different attacks, such as session hijacking, phishing, malware distribution, and data exfiltration. Due to the nature of this type of attack, it can be difficult to detect and track, leading to potentially dangerous consequences for both patients and healthcare providers. It is, therefore, crucial that organizations using PacsOne Server take immediate action to mitigate the risks posed by this vulnerability.

By leveraging the pro features of the s4e.io platform, healthcare organizations can stay up-to-date with the latest vulnerabilities and security threats facing their digital assets. This advanced security solution offers comprehensive vulnerability scanning, threat intelligence, and asset discovery capabilities, allowing businesses to proactively manage their risk and strengthen their security posture. By partnering with s4e.io, healthcare organizations can secure their sensitive data while complying with industry regulations and maintaining the trust of their patients.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against this vulnerability, including:

  • Upgrading to the latest version of PacsOne Server (7.1.1 or later)
  • Deploying a web application firewall (WAF)
  • Enforcing input validation and sanitization practices
  • Enabling Content Security Policy (CSP)
  • Monitoring web application logs and network traffic for suspicious activities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-29164 scanner - Cross-Site Scripting (XSS) vulnerability in PacsOne Server (PACS Server In One Box) | S4E