Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 2025.MS4
affected
Description
The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version before 2025.MS4
References
cert.pl/en/posts/2026/03/CVE-2025-10350/
www.cgm.com/pol_pl/products/szpital/cgm-clininet.html