Home

Description

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

PUBLISHED Reserved 2025-09-01 | Published 2026-03-02 | Updated 2026-03-02 | Assigner CERT-PL




HIGH: 7.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-639 Authorization Bypass Through User-Controlled Key

Product status

Default status
unaffected

Any version before 2025.MS4
affected

References

cert.pl/en/posts/2026/03/CVE-2025-10350/ third-party-advisory

www.cgm.com/pol_pl/products/szpital/cgm-clininet.html product

cve.org (CVE-2025-58402)

nvd.nist.gov (CVE-2025-58402)

Download JSON