CVE-2025-30044: Cgm Clininet
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl", the parameters are not sufficiently normalized, which enables code injection.
Affected products
- Cgm Cgm Clininet: before 2025.MS2 (fixed in 2025.MS2)
Published 2026-03-02. Last modified 2026-06-17.