CVSS
No CVSS.
T
he CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages and attachments belonging to other users.
References
Configurations
No configuration.
History
02 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-02 12:16
Updated : 2026-03-02 20:29
NVD link : CVE-2025-58402
Mitre link : CVE-2025-58402
CVE.ORG link : CVE-2025-58402
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key