CVE 9 CRITICAL

Conditional RCE via the “system” function_CVE-2025-30055

9 / 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.

Basic Information

ID CVE-2025-30055
Source CERT-PL
Published Aug 27, 2025 at 10:22

Affected Product

Vendor CGM
Product CGM CLININET
Affected Versions CGM CGM CLININET 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.