CVE-2025-30036: Cgm Clininet
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Stored XSS vulnerability exists in the "Oddział" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.
Affected products
- Cgm Cgm Clininet: before 2024.MS4 (fixed in 2024.MS4)
Published 2025-08-27. Last modified 2026-06-17.