CGM CLININET Code Injection Vulnerability

Vulnerability

A code injection vulnerability has been identified in CGM CLININET software, affecting all versions prior to 2024.MS4. The issue arises in the 'system' function, which processes untrusted user input. When the 'EnableJSCaching' option is activated, this vulnerability can be exploited by executing arbitrary code through the 'Module' parameter.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the server where CGM CLININET is running.

Added: Aug 27, 2025, 11:22 AM
Updated: Aug 27, 2025, 11:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
7.4
remediation
0.0
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.