CVE-2025-30060: Cgm Clininet

Medium severity, CVSS 6.9. EPSS: 0.2% chance of exploitation in the next 30 days.

In the ReturnUserUnitsXML.pl service, the "getUserInfo" function is vulnerable to SQL injection through the "UserID" parameter.

Affected products

  • Cgm Cgm Clininet: before 2024.MS4 (fixed in 2024.MS4)

Published 2025-08-27. Last modified 2026-06-17.