CGM CLININET是德国CGM公司的一款医院信息管理系统。 CGM CLININET存在安全漏洞,该漏洞源于未实施任何防止点击劫持攻击的机制,可能导致攻击者将应用程序嵌入恶意制作的IFRAME中并诱使用户执行意外操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CGM | CGM CLININET | 0 ~ 2025.MS3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-58406 | Lack of HTTP Response Headers | |
| CVE-2025-58402 | Insecure Direct Object Reference Message ID | |
| CVE-2025-30042 | Session generation possible with certificate number only | |
| CVE-2025-30035 | Lack of API authentication allowing session generation for any user | |
| CVE-2025-30062 | SQL injection in CheckUnitCodeAndKey.pl | |
| CVE-2025-30044 | RCE on uhcapache user permissions | |
| CVE-2025-10350 | SQL injection in CGM NETRAAD |
No comments yet