Home
MEDIUM: 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 2025.MS3
affected
Description
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.
Problem types
CWE-693 Protection Mechanism Failure
Product status
Any version before 2025.MS3
References
cert.pl/en/posts/2026/03/CVE-2025-10350/
www.cgm.com/pol_pl/products/szpital/cgm-clininet.html