SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Mar 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cgm
Cgm cgm Netraad |
|
| Vendors & Products |
Cgm
Cgm cgm Netraad |
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0. | |
| Title | SQL injection in CGM NETRAAD | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2026-03-02T11:09:37.785Z
Updated: 2026-03-02T13:23:30.175Z
Reserved: 2025-09-12T10:33:47.576Z
Link: CVE-2025-10350
Updated: 2026-03-02T13:23:24.546Z
Status : Awaiting Analysis
Published: 2026-03-02T12:15:59.547
Modified: 2026-03-02T20:29:29.330
Link: CVE-2025-10350
No data.