CVE-2025-58402 PUBLISHED

Insecure Direct Object Reference Message ID

Assigner: CERT-PL
Reserved: 01.09.2025 Published: 02.03.2026 Updated: 02.03.2026

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor CGM
Product CGM CLININET
Versions Default: unaffected
  • affected from 0 to 2025.MS4 (excl.)

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE