CVE-2025-58405
MEDIUMCGM CLININET < 2025.ms3 - Clickjacking via Unrestricted UI Layer Embedding
Title source: llmDescription
The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an attacker can embed the application inside a maliciously crafted IFRAME and trick users into performing unintended actions, including potentially bypassing CSRF/XSRF defenses.
References (2)
Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/en/posts/2026/03/CVE-2025-10350/
Various Sources product
https://www.cgm.com/pol_pl/products/szpital/cgm-clininet.html
Scores
CVSS v3
6.1
EPSS
0.0017
EPSS Percentile
6.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1021
Status
published
Products (1)
cgm/clininet
< 2025.ms3
Published
Mar 02, 2026
Tracked Since
Mar 02, 2026