Back to Database
Status published
High
CVE-2025-2264
Santesoft Sante PACS Server Path Traversal Information Disclosure
Vulnerability Description
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2264
Credits & Attribution
No credits recorded in the NVD database.
More from Santesoft
View All →CVE-2025-5307
Santesoft Sante DICOM Viewer Pro Out-of-bounds Read
High
8.4
CVE-2025-54862
Santesoft Sante PACS Server Cross-site Scripting
Medium
4.8
CVE-2025-54759
Santesoft Sante PACS Server Cross-site Scripting
Medium
5.1
CVE-2025-54156
Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
Critical
9.1
CVE-2025-53948
Santesoft Sante PACS Server Double Free
High
8.7
Affected Vendor
Santesoft
View all reports →Affected Software
Sante PACS Server
Vulnerable Versions:
4.1.0, 4.2.0
Timeline
Official Publish:
March 13th, 2025
Last Modified:
March 14th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N