CGM NETRAAD是德国CGM公司的一个放射科信息系统与影像存档系统。 CGM NETRAAD 7.9.0之前版本存在SQL注入漏洞,该漏洞源于处理C-FIND查询时存在SQL注入,可能导致数据库访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CGM | CGM NETRAAD | 0 ~ 7.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-58405 | Lack of protection mechanisms against Clickjacking attacks | |
| CVE-2025-58406 | Lack of HTTP Response Headers | |
| CVE-2025-58402 | Insecure Direct Object Reference Message ID | |
| CVE-2025-30042 | Session generation possible with certificate number only | |
| CVE-2025-30035 | Lack of API authentication allowing session generation for any user | |
| CVE-2025-30062 | SQL injection in CheckUnitCodeAndKey.pl | |
| CVE-2025-30044 | RCE on uhcapache user permissions |
No comments yet