logo

Vulnerabilities in CGM CLININET software

ID: a1659702-6c3f-5d54-8464-b064973318e4

STIX ID: report--a1659702-6c3f-5d54-8464-b064973318e4

Feed Name: CERT Polska

Threat Score
80/100

Date Published: 2025-08-27

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska coordinated disclosure describes 17 CVEs impacting CGM CLININET (affecting versions prior to various 2024/2025 maintenance releases). The vulnerabilities include arbitrary code/command injection, multiple SQL injection issues, stored XSS, missing authentication on internal endpoints, and leakage of session IDs and configuration data — collectively enabling session hijacking, credential disclosure, and potential full administrative compromise; users are advised to apply vendor patches and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.