CVE-2025-12921

MEDIUM

OpenClinica Community Edition <3.12.2/3.13 - XML Injection

Title source: llm
STIX 2.1

Description

A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknown functionality of the file /ImportCRFData?action=confirm of the component CRF Data Import. Such manipulation of the argument xml_file leads to xml injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-91
Status published
Products (2)
openclinica/openclinica 3.12.2
openclinica/openclinica 3.13
Published Nov 10, 2025
Tracked Since Feb 18, 2026