Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
{
"binaries": [
{
"binary_name": "liborthancframework-dev",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "liborthancframework1",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "orthanc",
"binary_version": "1.10.0+dfsg-1"
},
{
"binary_name": "orthanc-dev",
"binary_version": "1.10.0+dfsg-1"
}
]
}