Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-30037 1 Cgm 1 Clininet 2025-08-29 N/A
The system exposes several endpoints, typically including "/int/" in their path, that should be restricted to internal services, but are instead publicly accessible without authentication to any host able to reach the application server on port 443/tcp.
CVE-2025-30036 1 Cgm 1 Clininet 2025-08-29 N/A
Stored XSS vulnerability exists in the "OddziaƂ" (Ward) module, in the death diagnosis description field, and allows the execution of arbitrary JavaScript code. This can lead to session hijacking of other users and potentially to privilege escalation up to full administrative rights.