CVE-2025-30058: Cgm Clininet

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.

Affected products

  • Cgm Cgm Clininet: before 2024.MS4 (fixed in 2024.MS4)

Published 2025-08-27. Last modified 2026-06-17.