Filtered by vendor Cgm Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-30061 1 Cgm 1 Clininet 2025-08-29 N/A
In the "utils/Reporter/OpenReportWindow.pl" service, there is an SQL injection vulnerability through the "UserID" parameter.
CVE-2025-30036 1 Cgm 1 Clininet 2025-08-29 N/A
Stored XSS vulnerability exists in the "OddziaƂ" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.