Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CGM CLININET — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in CGM CLININET, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities for the CGM CLININET product, categorized by Common Weakness Enumeration (CWE) types and tagged for easy reference. It aggregates known flaws discovered in this clinical software environment, focusing on the period from 2018 to the present. This comprehensive collection is designed to help security professionals, auditors, and administrators navigate the complex landscape of risks associated with CGM CLININET. By centralizing this data, the page allows users to track vendor advisories and updates as they are released, providing a clear timeline of security patches and remediation efforts. Additionally, it enables a deeper understanding of specific weakness classes affecting this software, such as injection flaws, broken access control, or security misconfigurations, by showing their prevalence and impact over time. Users can also look up a product's vulnerability history to identify recurring issues or persistent vulnerabilities that may require long-term mitigation strategies. This resource is particularly valuable for organizations managing compliance requirements or conducting risk assessments, as it provides a transparent view of the security posture of CGM CLININET. The information is sourced from public disclosures, vendor notices, and security research, ensuring accuracy and relevance. By examining these details, stakeholders can make informed decisions about patch management, configuration hardening, and overall security planning for their clinical IT infrastructure.

Vendor: CGM

CVE IDTitleCVSSSeverityPublished
CVE-2025-58406 Lack of HTTP Response Headers CWE-693 6.5AIMediumAI2026-03-02
CVE-2025-58405 Lack of protection mechanisms against Clickjacking attacks CWE-1021 6.5AIMediumAI2026-03-02
CVE-2025-58402 Insecure Direct Object Reference Message ID CWE-639 7.5AIHighAI2026-03-02
CVE-2025-30062 SQL injection in CheckUnitCodeAndKey.pl CWE-89 9.8AICriticalAI2026-03-02
CVE-2025-30044 RCE on uhcapache user permissions CWE-78 9.8AICriticalAI2026-03-02
CVE-2025-30042 Session generation possible with certificate number only CWE-603 6.6AIMediumAI2026-03-02
CVE-2025-30035 Lack of API authentication allowing session generation for any user CWE-306 9.8AICriticalAI2026-03-02
CVE-2025-30064 Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key CWE-912 9.1AICriticalAI2025-08-27
CVE-2025-30063 Excessive permissions on configuration files containing database logins and passwords CWE-732 7.1AIHighAI2025-08-27
CVE-2025-30061 SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameter CWE-89 9.8AICriticalAI2025-08-27
CVE-2025-30060 SQL injection in ReturnUserUnitsXML.pl via the UserID parameter CWE-89 9.8AICriticalAI2025-08-27
CVE-2025-30059 Authenticated SQL injection in PrepareCDExportJSON.pl CWE-89 9.8AICriticalAI2025-08-27
CVE-2025-30058 SQL injection in getPatientIdentifier function of PatientService.pl CWE-89 9.8AICriticalAI2025-08-27
CVE-2025-30057 Authenticated RCE with uhcapache privileges in ConvertToPDF CWE-94 9.8AICriticalAI2025-08-27
CVE-2025-30056 Calling system commands via RunCommand CWE-94 9.8AICriticalAI2025-08-27
CVE-2025-30055 Conditional RCE via the "system" function CWE-94 9.8AICriticalAI2025-08-27
CVE-2025-30048 Unauthenticated access to module configuration endpoint CWE-306 7.5AIHighAI2025-08-27
CVE-2025-30041 Missing authentication in APIs returning statistical data along with session IDs CWE-306 7.5AIHighAI2025-08-27
CVE-2025-30040 Missing authentication in API returning request logs containing session IDs CWE-306 5.3AIMediumAI2025-08-27
CVE-2025-30039 Missing authentication in API returning a list of all active sessions CWE-306 9.8AICriticalAI2025-08-27
CVE-2025-30038 Session ID leakage in Zone.Identifier of downloaded files CWE-1230 3.3AILowAI2025-08-27
CVE-2025-30037 Missing authentication in APIs allowing data retrieval and modification CWE-306 7.5AIHighAI2025-08-27
CVE-2025-30036 Stored XSS permitting session takeover of arbitrary user CWE-79 7.6AIHighAI2025-08-27
CVE-2025-2313 RCE via Print.pl in uhcPrintServerPrint CWE-94 9.8AICriticalAI2025-08-27

All 24 known CVE vulnerabilities affecting CGM CLININET with full Chinese analysis, references, and POCs where available.