Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CGM — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting CGM. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CGM primarily functions as a comprehensive security management platform, aggregating data from various sources to provide centralized visibility into organizational risk postures. With twenty-five recorded CVEs, the software has historically exhibited vulnerabilities typical of complex enterprise applications, including remote code execution, cross-site scripting, and privilege escalation flaws. These defects often stem from insufficient input validation or improper access control mechanisms within its web interface and API endpoints. While no single catastrophic incident has defined its public history, the recurring nature of these vulnerabilities suggests persistent challenges in securing its integration layers. Security researchers have frequently highlighted the potential for unauthorized data access and system compromise, urging administrators to prioritize regular patching and strict network segmentation. The platform’s reliance on third-party components further complicates its security landscape, requiring diligent dependency management to mitigate emerging threats effectively.

Found 24 results / 25 Clear Filters
Top products by CGM: CGM CLININET CGM NETRAAD
CVE ID Title CVSS Severity Published
CVE-2025-58406 Lack of HTTP Response Headers — CGM CLININET CWE-693 6.5AI Medium AI 2026-03-02
CVE-2025-58405 Lack of protection mechanisms against Clickjacking attacks — CGM CLININET CWE-1021 6.5AI Medium AI 2026-03-02
CVE-2025-58402 Insecure Direct Object Reference Message ID — CGM CLININET CWE-639 7.5AI High AI 2026-03-02
CVE-2025-30062 SQL injection in CheckUnitCodeAndKey.pl — CGM CLININET CWE-89 9.8AI Critical AI 2026-03-02
CVE-2025-30044 RCE on uhcapache user permissions — CGM CLININET CWE-78 9.8AI Critical AI 2026-03-02
CVE-2025-30042 Session generation possible with certificate number only — CGM CLININET CWE-603 6.6AI Medium AI 2026-03-02
CVE-2025-30035 Lack of API authentication allowing session generation for any user — CGM CLININET CWE-306 9.8AI Critical AI 2026-03-02
CVE-2025-30064 Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key — CGM CLININET CWE-912 9.1AI Critical AI 2025-08-27
CVE-2025-30063 Excessive permissions on configuration files containing database logins and passwords — CGM CLININET CWE-732 7.1AI High AI 2025-08-27
CVE-2025-30061 SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameter — CGM CLININET CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30060 SQL injection in ReturnUserUnitsXML.pl via the UserID parameter — CGM CLININET CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30059 Authenticated SQL injection in PrepareCDExportJSON.pl — CGM CLININET CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30058 SQL injection in getPatientIdentifier function of PatientService.pl — CGM CLININET CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30057 Authenticated RCE with uhcapache privileges in ConvertToPDF — CGM CLININET CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30056 Calling system commands via RunCommand — CGM CLININET CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30055 Conditional RCE via the "system" function — CGM CLININET CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30048 Unauthenticated access to module configuration endpoint — CGM CLININET CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30041 Missing authentication in APIs returning statistical data along with session IDs — CGM CLININET CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30040 Missing authentication in API returning request logs containing session IDs — CGM CLININET CWE-306 5.3AI Medium AI 2025-08-27
CVE-2025-30039 Missing authentication in API returning a list of all active sessions — CGM CLININET CWE-306 9.8AI Critical AI 2025-08-27
CVE-2025-30038 Session ID leakage in Zone.Identifier of downloaded files — CGM CLININET CWE-1230 3.3AI Low AI 2025-08-27
CVE-2025-30037 Missing authentication in APIs allowing data retrieval and modification — CGM CLININET CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30036 Stored XSS permitting session takeover of arbitrary user — CGM CLININET CWE-79 7.6AI High AI 2025-08-27
CVE-2025-2313 RCE via Print.pl in uhcPrintServerPrint — CGM CLININET CWE-94 9.8AI Critical AI 2025-08-27

This page lists every published CVE security advisory associated with CGM. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.