By injecting malicious content, a remote attacker can perform a reflected cross-site scripting (XSS) attack. Cross-site scripting affects PacsOne Server (PACS Server In One Box) versions below 7.1.1. (XSS).