Vulnerability Summary Title: NovaRad NovaPACS Diagnostics Viewer 8.5 - XML External Entity Injection (File Disclosure) Vulnerable App: NovaPACS Diagnostics Viewer 8.5 Vulnerability Type: XML External Entity (XXE) Injection Affected Version: 8.5.19.75 (Diagnostics Viewer, Study Browser) Platform: XML Disclosure Date: 2018-09-06 Advisory ID: ZSL-2018-5488 Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5488.php Description NovaPACS suffers from an unauthenticated XML External Entity (XXE) injection vulnerability using the DTD parameter entities technique. Attack Example This example demonstrates an attacker's file that triggers the vulnerability to retrieve data from the file. Conclusion The screenshot reveals that the NovaRad NovaPACS Diagnostics Viewer 8.5 is vulnerable to an XXE injection that can lead to file disclosure, exposing sensitive data if exploited.