Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-58402

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-58402
  • Cgm » Clininet » Version: Any
    cpe:2.3:a:cgm:clininet:*


Contact Us

Shodan ® - All rights reserved