{"id":"CVE-2026-10173","summary":"Orthanc Explorer 2 URL StudyList.vue cross site scripting","details":"A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the component URL Handler. This manipulation of the argument remote-source causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 21f78ce5da668bf5233efcd1896ec7c6e3b22eae. Applying a patch is the recommended action to fix this issue.","modified":"2026-08-04T11:49:10.658441250Z","published":"2026-05-31T07:00:12.012Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-79","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10173.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10173.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10173"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-10173"},{"type":"ADVISORY","url":"https://vuldb.com/submit/819559"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/367430"},{"type":"REPORT","url":"https://github.com/orthanc-server/orthanc-explorer-2/issues/108"},{"type":"REPORT","url":"https://vuldb.com/vuln/367430/cti"},{"type":"FIX","url":"https://github.com/rafaelsouzars/orthanc-explorer-2/commit/21f78ce5da668bf5233efcd1896ec7c6e3b22eae"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/orthanc-server/orthanc-explorer-2","events":[{"introduced":"0cad3404b5a2142d176c36e1b6d6caafc2329cd0"},{"last_affected":"c75f3a1b95592deba1cdede3cb4d761d723566ca"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.2"},{"last_affected":"1.2"},{"introduced":"1.3"},{"last_affected":"1.3"},{"introduced":"1.4"},{"last_affected":"1.4"},{"introduced":"1.5"},{"last_affected":"1.5"},{"introduced":"1.6"},{"last_affected":"1.6"},{"introduced":"1.7"},{"last_affected":"1.7"},{"introduced":"1.8"},{"last_affected":"1.8"},{"introduced":"1.9"},{"last_affected":"1.9"},{"introduced":"1.10"},{"last_affected":"1.10"},{"introduced":"1.11"},{"last_affected":"1.11"},{"introduced":"1.12.0"},{"last_affected":"1.12.0"}]}}],"versions":["1.0","1.1","1.10","1.11","1.12.0","1.2","1.3","1.4","1.5","1.6","1.7","1.8","1.9","1.11.0","1.10.2","1.10.1","1.10.0","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.7.1","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.1","1.5.0","1.4.1","1.4.0","1.3.0","1.2.2","1.2.1","1.2.0","1.1.3","1.1.2","1.1.1","1.1.0","1.0.3","1.0.2","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10173.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}