Unknown · Cgm Clininet · CVE-2025-30044
**Name of the Vulnerable Software and Affected Versions**
CGM CLININET (affected versions not specified)
**Description**
The application suffers from insufficient input normalization in several API endpoints, leading to potential code injection. Specifically, the parameters passed to the following endpoints are not adequately sanitized: '/cgi-bin/CliniNET.prd/utils/usrlogstat simple.pl', '/cgi-bin/CliniNET.prd/utils/usrlogstat.pl', '/cgi-bin/CliniNET.prd/utils/userlogstat2.pl', and '/cgi-bin/CliniNET.prd/utils/dblogstat.pl'. This allows for the execution of arbitrary code through crafted input.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.