CGM CLININET是德国CGM公司的一款医院信息管理系统。 CGM CLININET存在访问控制错误漏洞,该漏洞源于身份验证可被完全绕过,可能导致会话劫持和权限提升。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CGM | CGM CLININET | 0 ~ 2025.MS4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-58405 | Lack of protection mechanisms against Clickjacking attacks | |
| CVE-2025-58406 | Lack of HTTP Response Headers | |
| CVE-2025-58402 | Insecure Direct Object Reference Message ID | |
| CVE-2025-30042 | Session generation possible with certificate number only | |
| CVE-2025-30062 | SQL injection in CheckUnitCodeAndKey.pl | |
| CVE-2025-30044 | RCE on uhcapache user permissions | |
| CVE-2025-10350 | SQL injection in CGM NETRAAD |
No comments yet