CGM CLININET Code Injection Vulnerability in Print.pl Service
Vulnerability
A code injection vulnerability has been identified in the CGM CLININET software, specifically within the Print.pl service. The issue arises in the 'uhcPrintServerPrint' function, where the 'CopyCounter' parameter can be manipulated to execute arbitrary code. This vulnerability affects all versions of CGM CLININET prior to the 2025.MS1 release.
Impact
Exploitation of this vulnerability allows for arbitrary code execution on the server where CGM CLININET is running.
Remediation
Users can update to CGM CLININET version 2025.MS1 or later to address this vulnerability.
Added: Aug 27, 2025, 11:26 AM
Updated: Aug 27, 2025, 11:26 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
7.4remediation
0.0relevance
0.4threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
